CVE-2024-20399

MEDIUM CISA KEV
Published Jul 1, 2024 Modified Oct 28, 2025 CWE-78

Description

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary commands as root on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of arguments that are passed to specific configuration CLI commands. An attacker could exploit this vulnerability by including crafted input as the argument of an affected configuration CLI command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of root. Note: To successfully exploit this vulnerability on a Cisco NX-OS device, an attacker must have Administrator credentials. The following Cisco devices already allow administrative users to access the underlying operating system through the bash-shell feature, so, for these devices, this vulnerability does not grant any additional privileges: Nexus 3000 Series Switches Nexus 7000 Series Switches that are running Cisco NX-OS Software releases 8.1(1) and later Nexus 9000 Series Switches in standalone NX-OS mode

CVSS v3.1 Score

6.0
MEDIUM
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild.

Added: Jul 2, 2024 Remediation due: Jul 23, 2024

Weakness Type (CWE)

CWE-78 OS Command Injection

Affected Products

Vendor Product
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nexus_7000
cisco nexus_7000_10-slot
cisco nexus_7000_18-slot
cisco nexus_7000_4-slot
cisco nexus_7000_9-slot
cisco nexus_7000_supervisor_1
cisco nexus_7000_supervisor_2
cisco nexus_7000_supervisor_2e
cisco nexus_7004
cisco nexus_7009
cisco nexus_7010
cisco nexus_7018
cisco nexus_7700
cisco nexus_7700_10-slot
cisco nexus_7700_18-slot
cisco nexus_7700_2-slot
cisco nexus_7700_6-slot
cisco nexus_7700_supervisor_2e
cisco nexus_7700_supervisor_3e
cisco nexus_7702
cisco nexus_7706
cisco nexus_7710
cisco nexus_7718
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco mds_9000
cisco mds_9100
cisco mds_9132t
cisco mds_9134
cisco mds_9140
cisco mds_9148
cisco mds_9148s
cisco mds_9148t
cisco mds_9200
cisco mds_9216
cisco mds_9216a
cisco mds_9216i
cisco mds_9222i
cisco mds_9250i
cisco mds_9396s
cisco mds_9396t
cisco mds_9500
cisco mds_9506
cisco mds_9509
cisco mds_9513
cisco mds_9700
cisco mds_9706
cisco mds_9710
cisco mds_9718
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nexus_3000
cisco nexus_3016
cisco nexus_3016q
cisco nexus_3048
cisco nexus_3064
cisco nexus_3064-32t
cisco nexus_3064-t
cisco nexus_3064-x
cisco nexus_3064t
cisco nexus_3064x
cisco nexus_3100
cisco nexus_3100-v
cisco nexus_3100-z
cisco nexus_3100v
cisco nexus_31108pc-v
cisco nexus_31108pv-v
cisco nexus_31108tc-v
cisco nexus_31128pq
cisco nexus_3132c-z
cisco nexus_3132q
cisco nexus_3132q-v
cisco nexus_3132q-x
cisco nexus_3132q-x\/3132q-xl
cisco nexus_3132q-xl
cisco nexus_3164q
cisco nexus_3172
cisco nexus_3172pq
cisco nexus_3172pq-xl
cisco nexus_3172pq\/pq-xl
cisco nexus_3172tq
cisco nexus_3172tq-32t
cisco nexus_3172tq-xl
cisco nexus_3200
cisco nexus_3232
cisco nexus_3232c
cisco nexus_3232c_
cisco nexus_3264c-e
cisco nexus_3264q
cisco nexus_3400
cisco nexus_3408-s
cisco nexus_34180yc
cisco nexus_34200yc-sm
cisco nexus_3432d-s
cisco nexus_3464c
cisco nexus_3500
cisco nexus_3524
cisco nexus_3524-x
cisco nexus_3524-x\/xl
cisco nexus_3524-xl
cisco nexus_3548
cisco nexus_3548-x
cisco nexus_3548-x\/xl
cisco nexus_3548-xl
cisco nexus_3600
cisco nexus_36180yc-r
cisco nexus_3636c-r
cisco nexus_9000
cisco nexus_9000_in_aci_mode
cisco nexus_9000_in_standalone
cisco nexus_9000_in_standalone_nx-os_mode
cisco nexus_9000v
cisco nexus_9200
cisco nexus_9200yc
cisco nexus_92160yc-x
cisco nexus_9221c
cisco nexus_92300yc
cisco nexus_92304qc
cisco nexus_9232e
cisco nexus_92348gc-x
cisco nexus_9236c
cisco nexus_9272q
cisco nexus_9300
cisco nexus_93108tc-ex
cisco nexus_93108tc-ex-24
cisco nexus_93108tc-fx
cisco nexus_93108tc-fx-24
cisco nexus_93108tc-fx3h
cisco nexus_93108tc-fx3p
cisco nexus_93120tx
cisco nexus_93128
cisco nexus_93128tx
cisco nexus_9316d-gx
cisco nexus_93180lc-ex
cisco nexus_93180tc-ex
cisco nexus_93180yc-ex
cisco nexus_93180yc-ex-24
cisco nexus_93180yc-fx
cisco nexus_93180yc-fx-24
cisco nexus_93180yc-fx3
cisco nexus_93180yc-fx3h
cisco nexus_93180yc-fx3s
cisco nexus_93216tc-fx2
cisco nexus_93240tc-fx2
cisco nexus_93240yc-fx2
cisco nexus_9332c
cisco nexus_9332d-gx2b
cisco nexus_9332d-h2r
cisco nexus_9332pq
cisco nexus_93360yc-fx2
cisco nexus_9336c-fx2
cisco nexus_9336c-fx2-e
cisco nexus_9336pq
cisco nexus_9336pq_aci
cisco nexus_9336pq_aci_spine
cisco nexus_9348d-gx2a
cisco nexus_9348gc-fx3
cisco nexus_9348gc-fxp
cisco nexus_93600cd-gx
cisco nexus_9364c
cisco nexus_9364c-gx
cisco nexus_9364d-gx2a
cisco nexus_9372px
cisco nexus_9372px-e
cisco nexus_9372tx
cisco nexus_9372tx-e
cisco nexus_9396px
cisco nexus_9396tx
cisco nexus_9408
cisco nexus_9432pq
cisco nexus_9500
cisco nexus_9500_16-slot
cisco nexus_9500_4-slot
cisco nexus_9500_8-slot
cisco nexus_9500_supervisor_a
cisco nexus_9500_supervisor_a\+
cisco nexus_9500_supervisor_b
cisco nexus_9500_supervisor_b\+
cisco nexus_9500r
cisco nexus_9504
cisco nexus_9508
cisco nexus_9516
cisco nexus_9536pq
cisco nexus_9636pq
cisco nexus_9716d-gx
cisco nexus_9736pq
cisco nexus_9800
cisco nexus_9804
cisco nexus_9808
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nx-os
cisco nexus_5000
cisco nexus_5010
cisco nexus_5020
cisco nexus_5500
cisco nexus_5548p
cisco nexus_5548up
cisco nexus_5596t
cisco nexus_5596up
cisco nexus_5600
cisco nexus_56128p
cisco nexus_5624q
cisco nexus_5648q
cisco nexus_5672up
cisco nexus_5672up-16g
cisco nexus_5696q

References

Frequently Asked Questions

What is CVE-2024-20399? +
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary commands as root on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of arguments that are passed to specific configuration CLI commands. An attacker could exploit this vulnerability by including crafted input as the argument of an affected configuration CLI command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of root. Note: To successfully exploit this vulnerability on a Cisco NX-OS device, an attacker must have Administrator credentials. The following Cisco devices already allow administrative users to access the underlying operating system through the bash-shell feature, so, for these devices, this vulnerability does not grant any additional privileges: Nexus 3000 Series Switches Nexus 7000 Series Switches that are running Cisco NX-OS Software releases 8.1(1) and later Nexus 9000 Series Switches in standalone NX-OS mode It has a CVSS v3.1 base score of 6.0 (MEDIUM). This vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild.
How severe is CVE-2024-20399? +
CVE-2024-20399 has a CVSS v3.1 score of 6.0 out of 10, rated MEDIUM. This is a medium-severity vulnerability that should be remediated as part of regular maintenance.
What products are affected by CVE-2024-20399? +
CVE-2024-20399 affects products from cisco, specifically: mds_9000, mds_9100, mds_9132t, mds_9134, mds_9140, mds_9148, mds_9148s, mds_9148t, mds_9200, mds_9216, mds_9216a, mds_9216i, mds_9222i, mds_9250i, mds_9396s, mds_9396t, mds_9500, mds_9506, mds_9509, mds_9513, mds_9700, mds_9706, mds_9710, mds_9718, nexus_3000, nexus_3016, nexus_3016q, nexus_3048, nexus_3064, nexus_3064-32t, nexus_3064-t, nexus_3064-x, nexus_3064t, nexus_3064x, nexus_3100, nexus_3100-v, nexus_3100-z, nexus_3100v, nexus_31108pc-v, nexus_31108pv-v, nexus_31108tc-v, nexus_31128pq, nexus_3132c-z, nexus_3132q, nexus_3132q-v, nexus_3132q-x, nexus_3132q-x\/3132q-xl, nexus_3132q-xl, nexus_3164q, nexus_3172, nexus_3172pq, nexus_3172pq-xl, nexus_3172pq\/pq-xl, nexus_3172tq, nexus_3172tq-32t, nexus_3172tq-xl, nexus_3200, nexus_3232, nexus_3232c, nexus_3232c_, nexus_3264c-e, nexus_3264q, nexus_3400, nexus_3408-s, nexus_34180yc, nexus_34200yc-sm, nexus_3432d-s, nexus_3464c, nexus_3500, nexus_3524, nexus_3524-x, nexus_3524-x\/xl, nexus_3524-xl, nexus_3548, nexus_3548-x, nexus_3548-x\/xl, nexus_3548-xl, nexus_3600, nexus_36180yc-r, nexus_3636c-r, nexus_5000, nexus_5010, nexus_5020, nexus_5500, nexus_5548p, nexus_5548up, nexus_5596t, nexus_5596up, nexus_5600, nexus_56128p, nexus_5624q, nexus_5648q, nexus_5672up, nexus_5672up-16g, nexus_5696q, nexus_7000, nexus_7000_10-slot, nexus_7000_18-slot, nexus_7000_4-slot, nexus_7000_9-slot, nexus_7000_supervisor_1, nexus_7000_supervisor_2, nexus_7000_supervisor_2e, nexus_7004, nexus_7009, nexus_7010, nexus_7018, nexus_7700, nexus_7700_10-slot, nexus_7700_18-slot, nexus_7700_2-slot, nexus_7700_6-slot, nexus_7700_supervisor_2e, nexus_7700_supervisor_3e, nexus_7702, nexus_7706, nexus_7710, nexus_7718, nexus_9000, nexus_9000_in_aci_mode, nexus_9000_in_standalone, nexus_9000_in_standalone_nx-os_mode, nexus_9000v, nexus_9200, nexus_9200yc, nexus_92160yc-x, nexus_9221c, nexus_92300yc, nexus_92304qc, nexus_9232e, nexus_92348gc-x, nexus_9236c, nexus_9272q, nexus_9300, nexus_93108tc-ex, nexus_93108tc-ex-24, nexus_93108tc-fx, nexus_93108tc-fx-24, nexus_93108tc-fx3h, nexus_93108tc-fx3p, nexus_93120tx, nexus_93128, nexus_93128tx, nexus_9316d-gx, nexus_93180lc-ex, nexus_93180tc-ex, nexus_93180yc-ex, nexus_93180yc-ex-24, nexus_93180yc-fx, nexus_93180yc-fx-24, nexus_93180yc-fx3, nexus_93180yc-fx3h, nexus_93180yc-fx3s, nexus_93216tc-fx2, nexus_93240tc-fx2, nexus_93240yc-fx2, nexus_9332c, nexus_9332d-gx2b, nexus_9332d-h2r, nexus_9332pq, nexus_93360yc-fx2, nexus_9336c-fx2, nexus_9336c-fx2-e, nexus_9336pq, nexus_9336pq_aci, nexus_9336pq_aci_spine, nexus_9348d-gx2a, nexus_9348gc-fx3, nexus_9348gc-fxp, nexus_93600cd-gx, nexus_9364c, nexus_9364c-gx, nexus_9364d-gx2a, nexus_9372px, nexus_9372px-e, nexus_9372tx, nexus_9372tx-e, nexus_9396px, nexus_9396tx, nexus_9408, nexus_9432pq, nexus_9500, nexus_9500_16-slot, nexus_9500_4-slot, nexus_9500_8-slot, nexus_9500_supervisor_a, nexus_9500_supervisor_a\+, nexus_9500_supervisor_b, nexus_9500_supervisor_b\+, nexus_9500r, nexus_9504, nexus_9508, nexus_9516, nexus_9536pq, nexus_9636pq, nexus_9716d-gx, nexus_9736pq, nexus_9800, nexus_9804, nexus_9808, nx-os. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2024-20399? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2024-20399 — free, no signup required.

Start Free Scan