vulnerability
Cisco UCS Manager: CVE-2024-20397: Cisco NX-OS Software Image Verification Bypass Vulnerability
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
6 | (AV:L/AC:L/Au:N/C:P/I:C/A:N) | 2024-12-04 | 2024-12-05 | 2025-02-21 |
Severity
6
CVSS
(AV:L/AC:L/Au:N/C:P/I:C/A:N)
Published
2024-12-04
Added
2024-12-05
Modified
2025-02-21
Description
A vulnerability in the bootloader of Cisco NX-OS Software could allow an unauthenticated attacker with physical access to an affected device, or an authenticated, local attacker with administrative credentials, to bypass NX-OS image signature verification.
This vulnerability is due to insecure bootloader settings. An attacker could exploit this vulnerability by executing a series of bootloader commands. A successful exploit could allow the attacker to bypass NX-OS image signature verification and load unverified software.
Solution
cisco-ucs-manager-upgrade-latest

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.