Target Industry

Indiscriminate, opportunistic targeting.

Overview

Cisco has released a patch for a command-line injection vulnerability in a network management platform used to manage switches in data centres. The flaw, tracked as CVE-2024-20399 (CVSS 6.0) can allow authenticated threat actors to execute arbitrary commands as root on the underlying operating system of an affected system. The issue affects the command line interface (CLI) of Cisco NX-OS Software, a product used to troubleshoot and perform maintenance on NX-OS-enabled devices, which use the Linux kernel at their core.

The flaw is being actively exploited by the Chinese state-sponsored actor, tracked as Velvet Ant. This exploitation led to the execution of custom malware that allowed Velvet Ant to remotely connect to compromised Cisco Nexus devices, upload additional files, and execute code on target systems.

Impact

If exploited, a threat actor with administrator credentials could execute arbitrary commands on the underlying operating system with root privileges. This could lead to complete system compromise, allowing the threat actor to modify system configurations, access sensitive information, or potentially disrupt normal operations. The vulnerability has a high impact on system integrity and confidentiality, although it does not directly affect system availability.

Affected Products

CVE-2024-20399 affects the following Cisco products if they were running a vulnerable release of Cisco NX-OS Software:

  • MDS 9000 Series Multilayer Switches (CSCwj97007)
  • Nexus 3000 Series Switches (CSCwj97009)1
  • Nexus 5500 Platform Switches (CSCwj97011)
  • Nexus 5600 Platform Switches (CSCwj97011)
  • Nexus 6000 Series Switches (CSCwj97011)
  • Nexus 7000 Series Switches (CSCwj94682)2
  • Nexus 9000 Series Switches in standalone NX-OS mode (CSCwj97009)1.

Cisco NX-OS Software releases 9.3(5) and later are not affected by this vulnerability, with the exception of the following Cisco platforms:

  • Nexus 3000 platforms:
  • N3K-C3264C-E
  • N3K-C3172PQ-10GE
  • N3K-C3172PQ-10GE-XL
  • N3K-C3172TQ-10GT
  • N3K-C3548P-10GX

 

Nexus 9000 platforms:

  • N9K-C92348GC-X (fixed in Cisco NX-OS Software releases 10.4(3) and later)

Containment, Mitigations & Remediations

We strongly recommend that the software updates released by Cisco are applied as soon as possible.

Indicators of Compromise

No specific Indicators of Compromise (IoCs) are available currently.

Threat Landscape

Cisco Nexus occupies a significant proportion of the networking hardware market share. Given that threat actors generally utilise a combination of probability and asset value to determine which attack surfaces to focus on, such Cisco product vulnerabilities will likely become a prime target. Given that Cisco products have become an integral aspect of business operations, threat actors will continue to exploit vulnerabilities contained within the associated products to complete pre-defined objectives.

Threat Actor

The Chinese state actor, tracked as Velvet Ant, previously launched an operation at the end of 2023 involving the deployment of PlugX espionage trojan on F5 BIG-IP appliances to gain persistent access to target networks with the objective of extracting sensitive data and to maintain access to the target network for espionage. The pivoting to Cisco Nexus products marks a development in the unit’s intelligence collection goals, coinciding with Beijing’s Belt and Road initiative, as well as its 2049 centenary plans, which aim to enhance its global influence, whilst gaining the upper hand on its Western rivals.

Mitre Methodologies

Common Weakness Enumeration (CWE)

CWE-78 – Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’)

Further Information

SYGNIA Blog 

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content