Target Industry
Indiscriminate, opportunistic targeting.
Overview
Cisco has released a patch for a command-line injection vulnerability in a network management platform used to manage switches in data centres. The flaw, tracked as CVE-2024-20399 (CVSS 6.0) can allow authenticated threat actors to execute arbitrary commands as root on the underlying operating system of an affected system. The issue affects the command line interface (CLI) of Cisco NX-OS Software, a product used to troubleshoot and perform maintenance on NX-OS-enabled devices, which use the Linux kernel at their core.
The flaw is being actively exploited by the Chinese state-sponsored actor, tracked as Velvet Ant. This exploitation led to the execution of custom malware that allowed Velvet Ant to remotely connect to compromised Cisco Nexus devices, upload additional files, and execute code on target systems.
Impact
If exploited, a threat actor with administrator credentials could execute arbitrary commands on the underlying operating system with root privileges. This could lead to complete system compromise, allowing the threat actor to modify system configurations, access sensitive information, or potentially disrupt normal operations. The vulnerability has a high impact on system integrity and confidentiality, although it does not directly affect system availability.
Affected Products
CVE-2024-20399 affects the following Cisco products if they were running a vulnerable release of Cisco NX-OS Software:
- MDS 9000 Series Multilayer Switches (CSCwj97007)
- Nexus 3000 Series Switches (CSCwj97009)1
- Nexus 5500 Platform Switches (CSCwj97011)
- Nexus 5600 Platform Switches (CSCwj97011)
- Nexus 6000 Series Switches (CSCwj97011)
- Nexus 7000 Series Switches (CSCwj94682)2
- Nexus 9000 Series Switches in standalone NX-OS mode (CSCwj97009)1.
Cisco NX-OS Software releases 9.3(5) and later are not affected by this vulnerability, with the exception of the following Cisco platforms:
- Nexus 3000 platforms:
- N3K-C3264C-E
- N3K-C3172PQ-10GE
- N3K-C3172PQ-10GE-XL
- N3K-C3172TQ-10GT
- N3K-C3548P-10GX
Nexus 9000 platforms:
- N9K-C92348GC-X (fixed in Cisco NX-OS Software releases 10.4(3) and later)
Containment, Mitigations & Remediations
We strongly recommend that the software updates released by Cisco are applied as soon as possible.
Indicators of Compromise
No specific Indicators of Compromise (IoCs) are available currently.
Threat Landscape
Cisco Nexus occupies a significant proportion of the networking hardware market share. Given that threat actors generally utilise a combination of probability and asset value to determine which attack surfaces to focus on, such Cisco product vulnerabilities will likely become a prime target. Given that Cisco products have become an integral aspect of business operations, threat actors will continue to exploit vulnerabilities contained within the associated products to complete pre-defined objectives.
Threat Actor
The Chinese state actor, tracked as Velvet Ant, previously launched an operation at the end of 2023 involving the deployment of PlugX espionage trojan on F5 BIG-IP appliances to gain persistent access to target networks with the objective of extracting sensitive data and to maintain access to the target network for espionage. The pivoting to Cisco Nexus products marks a development in the unit’s intelligence collection goals, coinciding with Beijing’s Belt and Road initiative, as well as its 2049 centenary plans, which aim to enhance its global influence, whilst gaining the upper hand on its Western rivals.
Mitre Methodologies
Common Weakness Enumeration (CWE)
CWE-78 – Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’)
Further Information
SYGNIA Blog












