CVE-2024-20413

MEDIUM

Cisco NX-OS Software - Privilege Escalation

Title source: llm
STIX 2.1

Description

A vulnerability in Cisco NX-OS Software could allow an authenticated, local attacker with privileges to access the Bash shell to elevate privileges to network-admin on an affected device. This vulnerability is due to insufficient security restrictions when executing application arguments from the Bash shell. An attacker with privileges to access the Bash shell could exploit this vulnerability by executing crafted commands on the underlying operating system. A successful exploit could allow the attacker to create new users with the privileges of network-admin.

Scores

CVSS v3 6.7
EPSS 0.0004
EPSS Percentile 13.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-862
Status published
Products (50)
Cisco/Cisco NX-OS Software 10.1(1)
Cisco/Cisco NX-OS Software 10.1(2)
Cisco/Cisco NX-OS Software 10.1(2t)
Cisco/Cisco NX-OS Software 10.2(1)
Cisco/Cisco NX-OS Software 10.2(1q)
Cisco/Cisco NX-OS Software 10.2(2)
Cisco/Cisco NX-OS Software 10.2(2a)
Cisco/Cisco NX-OS Software 10.2(3)
Cisco/Cisco NX-OS Software 10.2(3t)
Cisco/Cisco NX-OS Software 10.2(3v)
... and 40 more
Published Aug 28, 2024
Tracked Since Feb 18, 2026