Search This Blog

Powered by Blogger.

Blog Archive

Labels

Cisco Patches NX-OS Zero-Day Exploited by Chinese Attackers

The bug was exploited to install previously unknown malware as root on susceptible switches.

 

Cisco patched a NX-OS zero-day, identified as CVE-2024-20399 (CVSS score of 6.0), which the China-linked group Velvet Ant used to deploy previously unidentified malware as root on vulnerable switches. 

The bug exists in the CLI of Cisco NX-OS Software; an authenticated, local attacker can exploit it to execute arbitrary commands as root on the underlying operating system of the affected device. 

“This vulnerability is due to insufficient validation of arguments that are passed to specific configuration CLI commands. An attacker could exploit this vulnerability by including crafted input as the argument of an affected configuration CLI command.” reads the advisory issued by Cisco. “A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of root.” 

The IT giant emphasised that only hackers with Administrator privileges can successfully exploit this vulnerability on a Cisco NX-OS system. In April 2024, researchers informed the Cisco Product Security Incident Response Team (PSIRT) that the vulnerability was actively exploited in the wild. Sygnia, a cybersecurity firm, discovered the attacks in April 2024 and reported them to Cisco. The bug impacts the following devices: 

  • MDS 9000 Series Multilayer Switches (CSCwj97007) 
  • Nexus 3000 Series Switches (CSCwj97009) 
  • Nexus 5500 Platform Switches (CSCwj97011) 
  • Nexus 5600 Platform Switches (CSCwj97011) 
  • Nexus 6000 Series Switches (CSCwj97011) 
  • Nexus 7000 Series Switches (CSCwj94682) * 
  • Nexus 9000 Series Switches in standalone NX-OS mode (CSCwj97009) 

Cisco recommends that customers keep track of the credentials used by administrative users network-admin and vdc-admin. Cisco offers the Cisco Software Checker to help customers assess whether their devices are susceptible to this issue. 

In late 2023, Sygnia researchers responded to a critical organization's problem, which they traced to the same China-linked threat actor 'Velvet Ant.' The cyberspies used customised malware on F5 BIG-IP appliances to get persistent access to the target organization's internal network and steal sensitive data.
Share it:

Cisco

CVE vulnerability

Vulnerabilities and Exploits

Zero-day Flaw