GPU VulnDB

Database/Firmware, BMC & network fabric

Cisco NX-OS CLI: **[KEV]** Command injection giving root on the switch's underlying OS from an admin CLI session

CVE-2024-20399Firmware, BMC & network fabricKnown exploitedcurated

Impact

**[KEV]** Command injection giving root on the switch's underlying OS from an admin CLI session; exploited in the wild by the Velvet Ant group, who used it to install persistent malware on the switch

Who can reach it

Network, authenticated administrator

What to do

NX-OS upgrade with fabric failover — one leaf at a time, relying on the fabric's redundancy; a spine upgrade on a rail-optimised GPU fabric costs measurable job throughput

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.