Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-20411

Опубликовано: 28 авг. 2024
Источник: nvd
CVSS3: 6.7
EPSS Низкий

Описание

A vulnerability in Cisco NX-OS Software could allow an authenticated, local attacker with privileges to access the Bash shell to execute arbitrary code as root on an affected device.

This vulnerability is due to insufficient security restrictions when executing commands from the Bash shell. An attacker with privileges to access the Bash shell could exploit this vulnerability by executing a specific crafted command on the underlying operating system. A successful exploit could allow the attacker to execute arbitrary code with the privileges of root.

EPSS

Процентиль: 13%
0.00044
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-267

Связанные уязвимости

CVSS3: 6.7
github
больше 1 года назад

A vulnerability in Cisco NX-OS Software could allow an authenticated, local attacker with privileges to access the Bash shell to execute arbitrary code as root on an affected device. This vulnerability is due to insufficient security restrictions when executing commands from the Bash shell. An attacker with privileges to access the Bash shell could exploit this vulnerability by executing a specific crafted command on the underlying operating system. A successful exploit could allow the attacker to execute arbitrary code with the privileges of root.

CVSS3: 6.7
fstec
больше 1 года назад

Уязвимость операционной системы Cisco NX-OS коммутаторов Cisco Nexus, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 13%
0.00044
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-267