A vulnerability in the bootloader of Cisco NX-OS Software could allow an unauthenticated attacker with physical access to an affected device, or an authenticated, local attacker with administrative credentials, to bypass NX-OS image signature verification.
This vulnerability is due to insecure bootloader settings. An attacker could exploit this vulnerability by executing a series of bootloader commands. A successful exploit could allow the attacker to bypass NX-OS image signature verification and load unverified software.
Metrics
Affected Vendors & Products
References
History
Wed, 04 Dec 2024 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 04 Dec 2024 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability in the bootloader of Cisco NX-OS Software could allow an unauthenticated attacker with physical access to an affected device, or an authenticated, local attacker with administrative credentials, to bypass NX-OS image signature verification. This vulnerability is due to insecure bootloader settings. An attacker could exploit this vulnerability by executing a series of bootloader commands. A successful exploit could allow the attacker to bypass NX-OS image signature verification and load unverified software. | |
Title | Cisco NX-OS Software Image Verification Bypass Vulnerability | |
Weaknesses | CWE-284 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: cisco
Published: 2024-12-04T16:13:13.890Z
Updated: 2024-12-04T21:39:35.478Z
Reserved: 2023-11-08T15:08:07.660Z
Link: CVE-2024-20397
Vulnrichment
Updated: 2024-12-04T19:27:45.801Z
NVD
Status : Received
Published: 2024-12-04T17:15:11.913
Modified: 2024-12-04T17:15:11.913
Link: CVE-2024-20397
Redhat
No data.