cbcvebase.
CVE-2024-20399
published 2024-07-01

CVE-2024-20399: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary commands…

PriorityP181medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2024-07-23
Exploited in the wild
EPSS
4.27%
90.0th percentile
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary commands as root on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of arguments that are passed to specific configuration CLI commands. An attacker could exploit this vulnerability by including crafted input as the argument of an affected configuration CLI command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of root. Note: To successfully exploit this vulnerability on a Cisco NX-OS device, an attacker must have Administrator credentials. The following Cisco devices already allow administrative users to access the underlying operating system through the bash-shell feature, so, for these devices, this vulnerability does not grant any additional privileges: Nexus 3000 Series Switches Nexus 7000 Series Switches that are running Cisco NX-OS Software releases 8.1(1) and later Nexus 9000 Series Switches in standalone NX-OS mode

Affected

581 ranges· showing 25
VendorProductVersion rangeFixed in
ciscocisco_nx-os_software
ciscocisco_nx-os_software
ciscocisco_nx-os_software
ciscocisco_nx-os_software
ciscocisco_nx-os_software
ciscocisco_nx-os_software
ciscocisco_nx-os_software
ciscocisco_nx-os_software
ciscocisco_nx-os_software
ciscocisco_nx-os_software
ciscocisco_nx-os_software
ciscocisco_nx-os_software
ciscocisco_nx-os_software
ciscocisco_nx-os_software
ciscocisco_nx-os_software
ciscocisco_nx-os_software
ciscocisco_nx-os_software
ciscocisco_nx-os_software
ciscocisco_nx-os_software
ciscocisco_nx-os_software
ciscocisco_nx-os_software
ciscocisco_nx-os_software
ciscocisco_nx-os_software
ciscocisco_nx-os_software
ciscocisco_nx-os_software

Detection & IOCsextracted from sources · hover to see the quote

process/usr/bin/sshd -p X
filenamesshd_operns
port57722
commandMonitor capture CAP export ftp://
commandMonitor capture CAP start
  • Hunt for rogue SSH daemons spawned on non-standard high ports (e.g. 57722) on Cisco NX-OS underlying Linux shell or Guestshell — a post-exploitation persistence indicator following CVE-2024-20399 exploitation.
  • Detect JumbledPath: a GO-compiled ELF x86-64 binary found in actor-configured Guestshell instances on Cisco Nexus devices, used for chained packet capture and log clearing.
  • Alert on AAA/TACACS+ server IP address changes in running configuration, which threat actors use to bypass access control after gaining root via CVE-2024-20399.
  • Detect GRE tunnel creation on Cisco NX-OS devices as a lateral movement and pivoting indicator post-exploitation.
  • Look for non-empty or unusually large .bash_history files on Cisco device underlying OS as an indicator of post-exploitation activity; also alert on clearing of auth.log, lastlog, wtmp, and btmp.
  • Monitor Cisco NX-OS devices for HTTP/HTTPS server activation on non-standard ports, which may indicate attacker-controlled management interfaces established after root access via CVE-2024-20399.
  • Profile network devices via NetFlow and port scanning for new ports opening or closing and unexpected traffic to/from (not traversing) the device, indicating post-exploitation changes.
  • Monitor PAM and OpenSSH binaries and key files for unauthorized modifications on Linux-based network devices; backdoored copies may allow secret-password login or credential harvesting.
  • Detect loopback interface IP address modifications on compromised switches used as SSH source to bypass ACLs during lateral movement.
  • Alert on configuration exfiltration over TFTP or FTP from Cisco NX-OS devices, a post-exploitation data collection technique observed after CVE-2024-20399 exploitation.
  • ·Velvet Ant exploited CVE-2024-20399 as a persistence/defense-evasion tool (CLI escape to OS), not for remote initial access — the attacker must already be authenticated as Administrator.

CVSS provenance

nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
vulncheck6.0MEDIUM
cisa6.7MEDIUM
vendor_cisco6.0MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.