CVE-2025-20161

CVSS 3.1 Score 5.1 of 10 (medium)

Details

Published Feb 26, 2025
CWE ID 78

Summary

CVE-2025-20161 is a vulnerability affecting Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode. An authenticated, local attacker with valid Administrator credentials can take advantage of insufficient validation in the software upgrade process to execute command injection attacks on the underlying operating system. This could lead to arbitrary command execution with root privileges. Attackers could exploit this issue by installing a crafted image. To mitigate this risk, administrators are strongly advised to validate the hash of any software image before installation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share