CVE-2024-20289: Cisco NX-OS Software
Medium severity, CVSS 4.4. EPSS: 0.2% chance of exploitation in the next 30 days.
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to execute arbitrary commands on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of arguments for a specific CLI command. An attacker could exploit this vulnerability by including crafted input as the argument of the affected command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of the currently logged-in user.
Affected products
- Cisco Cisco NX-OS Software: version 9.3(3) only; version 9.3(4) only; version 9.3(5) only; version 9.3(6) only; version 10.1(2) only; version 10.1(1) only; …
- Cisco Cisco NX-OS System Software In ACI Mode: version 16.0(2h) only; version 16.0(2j) only; version 16.0(3d) only; version 16.0(3e) only; version 16.0(4c) only; version 16.0(5h) only; …
Published 2024-08-28. Last modified 2026-06-17.