CVE-2024-20397: Cisco NX-OS Software
Medium severity, CVSS 5.2. EPSS: 0.3% chance of exploitation in the next 30 days.
A vulnerability in the bootloader of Cisco NX-OS Software could allow an unauthenticated attacker with physical access to an affected device, or an authenticated, local attacker with administrative credentials, to bypass NX-OS image signature verification. This vulnerability is due to insecure bootloader settings. An attacker could exploit this vulnerability by executing a series of bootloader commands. A successful exploit could allow the attacker to bypass NX-OS image signature verification and load unverified software.
Affected products
- Cisco Cisco NX-OS Software: version 8.2(5) only; version 7.3(5)D1(1) only; version 8.4(2) only; version 8.4(3) only; version 9.2(3) only; version 7.0(3)I5(2) only; …
- Cisco Cisco NX-OS System Software In ACI Mode: version 14.1(1j) only; version 14.0(3d) only; version 14.1(1k) only; version 13.2(1m) only; version 14.0(3c) only; version 13.2(2l) only; …
- Cisco Cisco Unified Computing System Managed: version 4.0(4c) only; version 4.0(2b) only; version 4.1(2a) only; version 4.0(1a) only; version 4.0(2a) only; version 4.0(1b) only; …
Published 2024-12-04. Last modified 2026-06-17.