CVE-2025-20161
published 2025-02-26CVE-2025-20161: A vulnerability in the software upgrade process of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow…
PriorityP433medium5.1CVSS 3.1
AVLACLPRHUINSUCLIHAN
EPSS
0.47%
37.8th percentile
A vulnerability in the software upgrade process of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an authenticated, local attacker with valid Administrator credentials to execute a command injection attack on the underlying operating system of an affected device.
This vulnerability is due to insufficient validation of specific elements within a software image. An attacker could exploit this vulnerability by installing a crafted image. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with root privileges.
Note: Administrators should validate the hash of any software image before installation.
Affected
125 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
CVSS provenance
nvdv3.15.1MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N
vendor_cisco5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Nexus 3000 and 9000 Series Switches Command Injection Vulnerability
vendor_cisco·2025-02-26·CVSS 5.1
CVE-2025-20161 [MEDIUM] CWE-78 Cisco Nexus 3000 and 9000 Series Switches Command Injection Vulnerability
Cisco Nexus 3000 and 9000 Series Switches Command Injection Vulnerability
A vulnerability in the software upgrade process of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an authenticated, local attacker with valid Administrator credentials to execute a command injection attack on the underlying operating system of an affected device.
This vulnerability is due to insufficient validation of specific elements within a software image. An attacker could exploit this vulnerability by installing a crafted image. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with root privileges.
Note: Administrators should validate the hash of any software image before installation.
Ci
Cisco
Cisco Nexus 3000 and 9000 Series Switches Command Injection Vulnerability
vendor_cisco·CVSS 3.1
CVE-2025-20161 Cisco Nexus 3000 and 9000 Series Switches Command Injection Vulnerability
CVE-2025-20161: Cisco Nexus 3000 and 9000 Series Switches Command Injection Vulnerability
A vulnerability in the software upgrade process of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an authenticated, local attacker with valid Administrator credentials to execute a command injection attack on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of specific elements within a software image. An attacker could exploit this vulnerability by installing a crafted image. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with root privileges. Note: Administrators should validate the hash of any software image before ins
GHSA
GHSA-wc27-6x2h-q38w: A vulnerability in the software upgrade process of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode coul
ghsa_unreviewed·2025-02-26
CVE-2025-20161 [MEDIUM] CWE-78 GHSA-wc27-6x2h-q38w: A vulnerability in the software upgrade process of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode coul
A vulnerability in the software upgrade process of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an authenticated, local attacker with valid Administrator credentials to execute a command injection attack on the underlying operating system of an affected device.
This vulnerability is due to insufficient validation of specific elements within a software image. An attacker could exploit this vulnerability by installing a crafted image. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with root privileges.
Note: Administrators should validate the hash of any software image before installation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-02-26
Published