CVE-2024-20411

CVSS 3.1 Score 6.7 of 10 (medium)

Details

Published Aug 28, 2024
Updated: Aug 29, 2024
CWE ID 267

Summary

CVE-2024-20411 is a vulnerability in Cisco NX-OS Software that allows an authenticated local attacker with Bash shell access to execute arbitrary code with root privileges. This issue arises from insufficient security restrictions when executing commands from the Bash shell, making it exploitable through a specifically crafted command. The vulnerability has a medium severity rating, with a base score of 6.7 and high impacts on integrity and confidentiality. Affected products include various models of Cisco NX-OS Software, and remediation involves applying patches provided by Cisco. Organizations are at risk of severe operational disruptions and unauthorized access if this vulnerability is exploited successfully.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share