Database/Firmware, BMC & network fabric
Cisco NX-OS CLI: Command injection giving root on the switch's underlying OS from an admin CLI session
CVSS 6.0CVE-2024-20399Firmware, BMC & network fabricKnown exploitedcurated
Impact
Command injection giving root on the switch's underlying OS from an admin CLI session; exploited in the wild by the Velvet Ant group, who used it to install persistent malware on the switch
Who can reach it
Network, authenticated administrator
What to do
NX-OS upgrade with fabric failover — one leaf at a time, relying on the fabric's redundancy; a spine upgrade on a rail-optimised GPU fabric costs measurable job throughput
References
Related entries
- Cisco NX-OS CLI: CLI command injection giving root-level execution on the switch OS for an authenticated adminCVE-2017-12334 · Cisco NX-OS CLIMedium
- Intel TDX SEAM loader (Seamldr): Sensitive information is not cleared before a resource is reused in the SEAM loaderCVE-2024-21850 · Intel TDX SEAM loader (Seamldr)Medium
- AMD SEV-SNP firmware - input validation: Improper input validation in SEV-SNP lets a malicious hypervisor read orCVE-2024-21978 · AMD SEV-SNP firmware - input validationMedium
- AMD Power Management Firmware (PMFW) - guest VM input validation causing GPU reset: Improper input validation in AMD'sCVE-2024-36346 · AMD Power Management Firmware (PMFW) - guest VM input validation causing GPU resetMedium
- Intel TDX module: The TDX module is the software that stands between the host/VMM and every confidential VM on the boxCVE-2024-39283 · Intel TDX moduleMedium
- GRUB2 (BFS filesystem parser): Integer overflow producing a heap out-of-bounds read in the BeFS parserCVE-2024-45779 · GRUB2 (BFS filesystem parser)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.