Todd Boudreau’s Post

View profile for Todd Boudreau, graphic

I coach growing leaders to reach their full potential.

BOLO Patch Now: Cisco Zero-Day Under Fire From Chinese APT By Elizabeth Montalbano; 2 July 2024 Cisco has patched a command-line injection flaw in a network management platform used to manage switches in data centers, which, according to researchers from Sygnia, already has been exploited by the China-backed threat group known as Velvet Ant. The bug (CVE-2024-20399, CVSS 6.0) can allow authenticated attackers to execute arbitrary command as root on the underlying operating system of an affected device. It's found in the command line interface (CLI) of Cisco NX-OS Software, which allows data center operations managers to troubleshoot and perform maintenance operations on NX-OS-enabled devices, which use the Linux kernel at their core. "This vulnerability is due to insufficient validation of arguments that are passed to specific configuration CLI commands," according to Cisco's advisory on the flaw. "An attacker could exploit this vulnerability by including crafted input as the argument of an affected configuration CLI command." https://lnkd.in/ewGUhVep

Patch Now: Cisco Zero-Day Under Fire From Chinese APT

Patch Now: Cisco Zero-Day Under Fire From Chinese APT

darkreading.com

To view or add a comment, sign in

Explore topics