CVE-2024-20289
CVSS V2 None
CVSS V3 None
Description
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to execute arbitrary commands on the underlying operating system of an affected device.
This vulnerability is due to insufficient validation of arguments for a specific CLI command. An attacker could exploit this vulnerability by including crafted input as the argument of the affected command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of the currently logged-in user.
Overview
- CVE ID
- CVE-2024-20289
- Assigner
- cisco
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-08-28T16:31:23.856Z
- Last Modified Date
- 2024-08-28T17:24:18.101Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxos-cmdinj-Lq6jsZhH |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-20289 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20289 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-08-29 13:06:40 | Added to TrackCVE |