CyberzSOC

Publication detail
← Back to advisories & guidance

2024-090: Multiple Vulnerabilities in Cisco NX-OS Software ↗ source

September 2, 2024 CERT-EU Advisory

Summary

The most severe of these is a high-severity denial-of-service (DoS) vulnerability in the DHCPv6 relay agent, which could allow an unauthenticated remote attacker to cause targeted devices to reload repeatedly, leading to a DoS condition. Additionally, several medium-severity vulnerabilities were addressed, including issues that could allow privilege escalation and unauthorised code execution [1,2]. ThevulnerabilityCVE-2024-20446,withaCVSSof8.6,isduetoimproperhandlingofspecific fieldsinDHCPv6messages. BysendingspeciallycraftedDHCPv6packetstoanaffecteddevice, an attacker could cause the dhcp_snoop process to crash and restart multiple times, eventually forcing the device to reload, resulting in a DoS condition [3]. Other vulnerabilities addressed in this update include a medium-severity Command Injection flaw in the NX-OS CLI that could allow local attackers to execute arbitrary commands with elevated privileges, and multiple medium-severity Privilege Escalation flaws in the NX-OS sandbox environment that could allow authenticated local attackers to escape the Python sandbox and gain unauthorised access to the underlying operating system.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-20446 8.6 High Cisco Cisco NX-OS Software A vulnerability in the DHCPv6 relay agent of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) …

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.