← Vulnerability feed

Vulnerability record · CVE-2024-20399 · published 1 July 2024

CVE-2024-20399: Cisco NX-OS CLI command injection allows root command execution

Cisco · Nx Os

Cisco NX-OS fails to properly validate arguments passed to specific configuration CLI commands, allowing OS command injection. An attacker who already holds Administrator credentials can inject crafted input to run arbitrary commands as root on the underlying operating system. The flaw matters because it converts administrative CLI access into full root-level control of the device.

6.7 CVSS 3.1 Medium CISA KEV since 2 Jul 2024 EPSS 4.3% · top 9.2% CWE-78 · OS command injection
6.7CVSS 3.1 base score
4.3%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary commands as root on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of arguments that are passed to specific configuration CLI commands. An attacker could exploit this vulnerability by including crafted input as the argument of an affected configuration CLI command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of root. Note: To successfully exploit this vulnerability on a Cisco NX-OS device, an attacker must have Administrator credentials. The following Cisco devices already allow administrative users to access the underlying operating system through the bash-shell feature, so, for these devices, this vulnerability does not grant any additional privileges: Nexus 3000 Series Switches Nexus 7000 Series Switches that are running Cisco NX-OS Software releases 8.1(1) and later Nexus 9000 Series Switches in standalone NX-OS mode

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe flaw requires Administrator credentials but yields root on network devices and is confirmed exploited in the wild per CISA KEV.

What it is

Cisco NX-OS fails to properly validate arguments passed to specific configuration CLI commands, allowing OS command injection. An attacker who already holds Administrator credentials can inject crafted input to run arbitrary commands as root on the underlying operating system. The flaw matters because it converts administrative CLI access into full root-level control of the device.

Impact

An attacker with Administrator credentials gains root-level command execution on the underlying NX-OS operating system, enabling full device compromise. On devices that already expose bash-shell to admins, the flaw grants no additional privilege.

Attack surface

Reached locally through the NX-OS CLI by supplying crafted arguments to affected configuration commands. Authentication is required at Administrator privilege level; no user interaction is needed.

Exploitation

CVE-2024-20399 is listed in CISA KEV with a due date of 2024-07-23, indicating known exploitation in the wild. EPSS is 0.04306 (90.6th percentile), and a third-party advisory links it to a China-nexus threat group exploiting it as a zero-day.

What to do

  • Apply the Cisco NX-OS software updates referenced in the vendor advisory cisco-sa-nxos-cmd-injection-xD9OhyOP.
  • If patching is not immediately possible, follow Cisco's documented workarounds or discontinue use of the affected product per CISA guidance.
  • Restrict and audit Administrator-level CLI accounts; remove unnecessary admin credentials and enforce least privilege.
  • Monitor and limit management-plane access to trusted networks and administrative hosts.

Detection

  • Review NX-OS CLI command logs for configuration commands containing shell metacharacters or unexpected argument strings.
  • Alert on Administrator account activity outside normal change windows or from unusual source addresses.
  • Hunt for unexpected root-level processes or files on NX-OS devices that indicate command execution via the CLI.
  • Correlate device logs with management-plane authentication events to spot credential misuse preceding command injection.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-20399 to the Known Exploited Vulnerabilities catalog on 2 July 2024 as "Cisco NX-OS Command Injection Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 23 July 2024.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-20399 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-0310Cisco nx-os out-of-bounds read vulnerabilityA vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacke…EPSS 4.1%9.8CVE-2018-0301Cisco nx-os improper input validation vulnerabilityA vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to craft a packet to the management int…EPSS 17%9.8CVE-2016-1453Cisco nx-os memory buffer overflow vulnerabilityBuffer overflow in the Overlay Transport Virtualization (OTV) GRE feature in Cisco NX-OS 5.0 through 7.3 on Nexus 7000 and 7700 devices allows remote…EPSS 8.1%9.8CVE-2016-1341Cisco nx-os permissions and access controls vulnerabilityCisco NX-OS 7.0(1)N1(1), 7.0(1)N1(3), and 7.0(4)N1(1) on Nexus 2000 Fabric Extender devices has a blank root password, which allows local users to ga…EPSS 1.1%9.1CVE-2021-1361Cisco nx-os vulnerabilityA vulnerability in the implementation of an internal file management service for Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switche…EPSS 1.6%9.0CVE-2015-4235Cisco application policy infrastructure controller \(apic\) permissions and access controls vulnerabilityCisco Application Policy Infrastructure Controller (APIC) devices with software before 1.0(3o) and 1.1 before 1.1(1j) and Nexus 9000 ACI devices with…EPSS 2.2%9.0CVE-2013-1179Cisco nx-os memory buffer overflow vulnerabilityMultiple buffer overflows in the (1) SNMP and (2) License Manager implementations in Cisco NX-OS on Nexus 7000 devices 4.x and 5.x before 5.2(5) and …EPSS 3.4%9.0CVE-2013-1180Cisco nx-os memory buffer overflow vulnerabilityBuffer overflow in the SNMP implementation in Cisco NX-OS on Nexus 7000 devices 4.x and 5.x before 5.2(5) and 6.x before 6.1(1) and MDS 9000 devices …EPSS 3.4%

Source: NIST National Vulnerability Database (record CVE-2024-20399), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.