CVE-2024-20399
published 2024-07-01CVE-2024-20399: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary commands…
PriorityP181medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2024-07-23
Exploited in the wild
EPSS
4.27%
90.0th percentile
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary commands as root on the underlying operating system of an affected device.
This vulnerability is due to insufficient validation of arguments that are passed to specific configuration CLI commands. An attacker could exploit this vulnerability by including crafted input as the argument of an affected configuration CLI command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of root.
Note: To successfully exploit this vulnerability on a Cisco NX-OS device, an attacker must have Administrator credentials. The following Cisco devices already allow administrative users to access the underlying operating system through the bash-shell feature, so, for these devices, this vulnerability does not grant any additional privileges:
Nexus 3000 Series Switches
Nexus 7000 Series Switches that are running Cisco NX-OS Software releases 8.1(1) and later
Nexus 9000 Series Switches in standalone NX-OS mode
Affected
581 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Hunt for rogue SSH daemons spawned on non-standard high ports (e.g. 57722) on Cisco NX-OS underlying Linux shell or Guestshell — a post-exploitation persistence indicator following CVE-2024-20399 exploitation. ↗
- →Detect JumbledPath: a GO-compiled ELF x86-64 binary found in actor-configured Guestshell instances on Cisco Nexus devices, used for chained packet capture and log clearing. ↗
- →Alert on AAA/TACACS+ server IP address changes in running configuration, which threat actors use to bypass access control after gaining root via CVE-2024-20399. ↗
- →Detect GRE tunnel creation on Cisco NX-OS devices as a lateral movement and pivoting indicator post-exploitation. ↗
- →Look for non-empty or unusually large .bash_history files on Cisco device underlying OS as an indicator of post-exploitation activity; also alert on clearing of auth.log, lastlog, wtmp, and btmp. ↗
- →Monitor Cisco NX-OS devices for HTTP/HTTPS server activation on non-standard ports, which may indicate attacker-controlled management interfaces established after root access via CVE-2024-20399. ↗
- →Profile network devices via NetFlow and port scanning for new ports opening or closing and unexpected traffic to/from (not traversing) the device, indicating post-exploitation changes. ↗
- →Monitor PAM and OpenSSH binaries and key files for unauthorized modifications on Linux-based network devices; backdoored copies may allow secret-password login or credential harvesting. ↗
- →Detect loopback interface IP address modifications on compromised switches used as SSH source to bypass ACLs during lateral movement. ↗
- →Alert on configuration exfiltration over TFTP or FTP from Cisco NX-OS devices, a post-exploitation data collection technique observed after CVE-2024-20399 exploitation. ↗
- ·Velvet Ant exploited CVE-2024-20399 as a persistence/defense-evasion tool (CLI escape to OS), not for remote initial access — the attacker must already be authenticated as Administrator. ↗
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
vulncheck6.0MEDIUM
cisa6.7MEDIUM
vendor_cisco6.0MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Cisco NX-OS Command Injection Vulnerability
cisa·2024-07-02·CVSS 6.7
CVE-2024-20399 [MEDIUM] CWE-78 Cisco NX-OS Command Injection Vulnerability
Vulnerability: Cisco NX-OS Command Injection Vulnerability
Affected: Cisco NX-OS
Cisco NX-OS contains a command injection vulnerability in the command line interface (CLI) that could allow an authenticated, local attacker to execute commands as root on the underlying operating system of an affected device.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxos-cmd-injection-xD9OhyOP; https://nvd.nist.gov/vuln/detail/CVE-2024-20399
Remediation Due Date: 2024-07-23
Cisco
Cisco NX-OS Software CLI Command Injection Vulnerability
vendor_cisco·2024-07-01·CVSS 6.0
CVE-2024-20399 [MEDIUM] CWE-78 Cisco NX-OS Software CLI Command Injection Vulnerability
Cisco NX-OS Software CLI Command Injection Vulnerability
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary commands as root on the underlying operating system of an affected device.
This vulnerability is due to insufficient validation of arguments that are passed to specific configuration CLI commands. An attacker could exploit this vulnerability by including crafted input as the argument of an affected configuration CLI command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of root.
Note: To successfully exploit this vulnerability on a Cisco NX-OS device, an attacker must have Administrator credentials. Th
Cisco
Cisco NX-OS Software CLI Command Injection Vulnerability
vendor_cisco·CVSS 3.1
CVE-2024-20399 Cisco NX-OS Software CLI Command Injection Vulnerability
CVE-2024-20399: Cisco NX-OS Software CLI Command Injection Vulnerability
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary commands as root on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of arguments that are passed to specific configuration CLI commands. An attacker could exploit this vulnerability by including crafted input as the argument of an affected configuration CLI command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of root . Note: To successfully exploit this vulnerability on a Cisco NX-OS device, an attacker must have Administrator
GHSA
GHSA-428g-3m2x-46jh: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underlyin
ghsa_unreviewed·2024-07-01
CVE-2024-20399 [MEDIUM] CWE-78 GHSA-428g-3m2x-46jh: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underlyin
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying operating system of an affected device.
This vulnerability is due to insufficient validation of arguments that are passed to specific configuration CLI commands. An attacker could exploit this vulnerability by including crafted input as the argument of an affected configuration CLI command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of root.
Note: To successfully exploit this vulnerability on a Cisco NX-OS device, an attacker must have Administrator credentials.
VulnCheck
Cisco NX-OS Command Injection Vulnerability
vulncheck·2024·CVSS 6.0
CVE-2024-20399 [MEDIUM] CWE-78 Cisco NX-OS Command Injection Vulnerability
Cisco NX-OS Command Injection Vulnerability
Cisco NX-OS contains a command injection vulnerability in the command line interface (CLI) that could allow an authenticated, local attacker to execute commands as root on the underlying operating system of an affected device.
Affected: Cisco NX-OS
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://www.sygnia.co/threat-reports-and-advisories/china-nexus-threat-group-velvet-ant-exploits-cisco-0-day/; https://www.zero-day.cz/database/894/; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxos-cmd-injection-xD9OhyOP; ht
No detection rules found.
No public exploits indexed.
Hackernews
China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade
blogs_hackernews·2026-06-12
CVE-2024-20399 China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade
Instead of hiding on the laptops and servers defenders watch most closely, a China-nexus group spent close to a decade hidden inside the Linux login system itself.
Sygnia, which tracks the group as Velvet Ant , says it backdoored the PAM and OpenSSH components that decide who is allowed to sign in, planting its access where ordinary cleanup could not reach it. The network it targeted had no direct internet access, so the group first staged through internet-facing systems to get there.
The earliest traces go back to 2016. Instead of dropping new
Talos
Weathering the storm: In the midst of a Typhoon
blogs_talos·2025-02-20·CVSS 9.8
[CRITICAL] Weathering the storm: In the midst of a Typhoon
## Weathering the storm: In the midst of a Typhoon
## Summary
Cisco Talos has been closely monitoring reports of widespread intrusion activity against several major U.S. telecommunications companies. The activity, initially reported in late 2024 and later confirmed by the U.S. government, is being carried out by a highly sophisticated threat actor dubbed Salt Typhoon. This blog highlights our observations on this campaign and identifies recommendations for detection and prevention of the actor’s activities.
Public reporting has indicated that the threat actor was able to gain access to core networking infrastructure in several instances and then use that infrastructure to collect a variety of information. There was only one case in which we found evidence suggesting that a Cisco vulnera
Talos
Weathering the storm: In the midst of a Typhoon
blogs_talos·2025-02-20·CVSS 9.8
[CRITICAL] Weathering the storm: In the midst of a Typhoon
## Summary
Cisco Talos has been closely monitoring reports of widespread intrusion activity against several major U.S. telecommunications companies. The activity, initially reported in late 2024 and later confirmed by the U.S. government, is being carried out by a highly sophisticated threat actor dubbed Salt Typhoon. This blog highlights our observations on this campaign and identifies recommendations for detection and prevention of the actor’s activities.
Public reporting has indicated that the threat actor was able to gain access to core networking infrastructure in several instances and then use that infrastructure to collect a variety of information. There was only one case in which we found evidence suggesting that a Cisco vulnerability (CVE-2018-0171) was likely abused. In all the
Bleepingcomputer
Cisco bug lets hackers run commands as root on UWRB access points
blogs_bleepingcomputer·2024-11-06·CVSS 10.0
CVE-2024-20418 [CRITICAL] Cisco bug lets hackers run commands as root on UWRB access points
## Cisco bug lets hackers run commands as root on UWRB access points
## Sergiu Gatlan
Cisco has fixed a maximum severity vulnerability that allows attackers to run commands with root privileges on vulnerable Ultra-Reliable Wireless Backhaul (URWB) access points that provide connectivity for industrial wireless automation.
Tracked as CVE-2024-20418 , this security flaw was found in Cisco's Unified Industrial Wireless Software's web-based management interface. Unauthenticated threat actors can exploit it in low-complexity command injection attacks that don't require user interaction.
"This vulnerability is due to improper validation of input to the web-based management interface. An attacker could exploit this vulnerability by sending crafted HTTP requests to the web-based management int
Bleepingcomputer
Cisco warns of backdoor admin account in Smart Licensing Utility
blogs_bleepingcomputer·2024-09-04·CVSS 9.8
CVE-2024-20439 [CRITICAL] Cisco warns of backdoor admin account in Smart Licensing Utility
## Cisco warns of backdoor admin account in Smart Licensing Utility
## Sergiu Gatlan
Cisco has removed a backdoor account in the Cisco Smart Licensing Utility (CSLU) that can be used to log into unpatched systems with administrative privileges.
CSLU is a Windows application that helps manage licenses and linked products on-premises without connecting them to Cisco's cloud-based Smart Software Manager solution.
The company says this critical vulnerability (CVE-2024-20439) allows unauthenticated attackers to log into unpatched systems remotely using an "undocumented static user credential for an administrative account."
"A successful exploit could allow the attacker to log in to the affected system with administrative privileges over the API of the Cisco Smart Licensing Utility applicat
Bleepingcomputer
Exploit released for Cisco SSM bug allowing admin password changes
blogs_bleepingcomputer·2024-08-08·CVSS 6.0
[MEDIUM] Exploit released for Cisco SSM bug allowing admin password changes
## Exploit released for Cisco SSM bug allowing admin password changes
## Sergiu Gatlan
Cisco warns that exploit code is now available for a maximum severity vulnerability that lets attackers change any user password on unpatched Cisco Smart Software Manager On-Prem (Cisco SSM On-Prem) license servers.
As a Cisco Smart Licensing component, Cisco SSM On-Prem helps manage accounts and product licenses on an organization's environment using a dedicated dashboard on the local network.
"The Cisco PSIRT is aware that proof-of-concept exploit code is available for the vulnerability that is described in this advisory," the company warned on Wednesday.
However, Cisco has yet to find evidence of attackers exploiting this security flaw (tracked as CVE-2024-20419) in the wild.
CVE-2024-20419 is c
Qualys
Cybersecurity Threat Landscape 2024 Midyear Review
blogs_qualys·2024-08-06
Cybersecurity Threat Landscape 2024 Midyear Review
## Table of Contents
Key Takeaways from the Threat Landscape Report 2024
Vulnerability and Threat Analysis in the Cybersecurity Landscape 2024
Cyber Threat Landscape 2024 A Detailed Review
Key Statistics and Their Impact on the 2024 Cybersecurity Landscape
Mid-2024s Most Exploited Vulnerabilities in the Cybersecurity Landscape
Conclusion
As we navigate the complexities of 2024, it’s crucial to pause and reflect on the evolving threat landscape that surrounds us. This moment offers a unique opportunity to scrutinize our triumphs and missteps, understand the events that have decisively shaped our environment, and consider those that have subtly influenced it. By extracting key lessons from our recent experiences, we can fortify our strategies and prepare more effectively for the emerg
Bleepingcomputer
Cisco SSM On-Prem bug lets hackers change any user's password
blogs_bleepingcomputer·2024-07-17·CVSS 8.6
[HIGH] Cisco SSM On-Prem bug lets hackers change any user's password
## Cisco SSM On-Prem bug lets hackers change any user's password
## Sergiu Gatlan
Cisco has fixed a maximum severity vulnerability that allows attackers to change any user's password on vulnerable Cisco Smart Software Manager On-Prem (Cisco SSM On-Prem) license servers, including administrators.
The flaw also impacts SSM On-Prem installations earlier than Release 7.0, known as Cisco Smart Software Manager Satellite (SSM Satellite).
As a Cisco Smart Licensing component, SSM On-Prem assists service providers and Cisco partners in managing customer accounts and product licenses.
Tracked as CVE-2024-20419, this critical security flaw is caused by an unverified password change weakness in SSM On-Prem's authentication system. Successful exploitation enables unauthenticated, remote attackers
Tenable
Cybersecurity Snapshot: CISA Tells Tech Vendors To Squash Command Injection Bugs, as OpenSSF Calls on Developers To Boost Security Skills
blogs_tenable·2024-07-12
Cybersecurity Snapshot: CISA Tells Tech Vendors To Squash Command Injection Bugs, as OpenSSF Calls on Developers To Boost Security Skills
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bleepingcomputer
CISA urges devs to weed out OS command injection vulnerabilities
blogs_bleepingcomputer·2024-07-10·CVSS 6.0
CVE-2024-20399 [MEDIUM] CISA urges devs to weed out OS command injection vulnerabilities
## CISA urges devs to weed out OS command injection vulnerabilities
## Sergiu Gatlan
CISA and the FBI urged software companies on Wednesday to review their products and eliminate path OS command injection vulnerabilities before shipping.
The advisory was released in response to recent attacks that exploited multiple OS command injection security flaws ( CVE-2024-20399 , CVE-2024-3400 , and CVE-2024-21887 ) to compromise Cisco , Palo Alto , and Ivanti network edge devices.
Velvet Ant, the Chinese state-sponsored threat actor that coordinated these attacks, deployed custom malware to gain persistence on hacked devices as part of a cyber espionage campaign.
"OS command injection vulnerabilities arise when manufacturers fail to properly validate and sanitize user input when constructing
Threat Intel
Velvet Ant (Velvet Ant)
threat_intel
Velvet Ant (Velvet Ant)
# Threat Actor Profile: Velvet Ant
ATT&CK ID: G1047
Also known as: Velvet Ant
## Overview
Velvet Ant is a threat actor operating since at least 2021. Velvet Ant is associated with complex persistence mechanisms, the targeting of network devices and appliances during operations, and the use of zero day exploits.(Citation: Sygnia VelvetAnt 2024A)(Citation: Sygnia VelvetAnt 2024B)
## Techniques (TTPs)
### Initial Access
- T1133 External Remote Services
Usage: Velvet Ant has leveraged access to internet-facing remote services to compromise and retain access to victim environments.(Citation: Sygnia VelvetAnt 2024A)
- T1078.003 Local Accounts
Usage: Velvet Ant accessed vulnerable Cisco switch devices using accounts with administrator privileges.(Citation: Sygnia VelvetAnt 2024B)
### Executio
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxos-cmd-injection-xD9OhyOPhttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxos-cmd-injection-xD9OhyOPhttps://www.sygnia.co/threat-reports-and-advisories/china-nexus-threat-group-velvet-ant-exploits-cisco-0-day/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-20399
2024-07-01
Published
2024-07-02
Added to CISA KEV
Exploited in the wild