CVE-2024-20397

Cisco NX-OS Software Image Verification Bypass Vulnerability

Severity
Medium 5.2
CVSS 3.1
Exploited
Not listed
EPSS
0.003
22.7th percentile
Discovered by
Third party
Published by the vendor
Published
Dec 4, 2024
Assigned by cisco

Description

A vulnerability in the bootloader of Cisco NX-OS Software could allow an unauthenticated attacker with physical access to an affected device, or an authenticated, local attacker with administrative credentials, to bypass NX-OS image signature verification.  This vulnerability is due to insecure bootloader settings. An attacker could exploit this vulnerability by executing a series of bootloader commands. A successful exploit could allow the attacker to bypass NX-OS image signature verification and load unverified software.

Weakness: CWE-284

Affected products

Vendor Product Category Matched by
Cisco Cisco NX-OS Software Routing & Switching cna-assigner
Cisco Cisco Unified Computing System (UCS) Other Products cna-assigner
Vendor-reported affected versions (3)
  • Cisco · Cisco NX-OS Software
  • Cisco · Cisco NX-OS System Software in ACI Mode
  • Cisco · Cisco Unified Computing System (Managed)