Unauthenticated Attacker Could Bypass NX-OS Image Signature Verification via Insecure Bootloader Settings
CVE-2024-20397
What is CVE-2024-20397?
A vulnerability exists in the bootloader of Cisco NX-OS Software that could potentially allow unauthenticated attackers with physical access, or authenticated local attackers with administrative privileges, to bypass the image signature verification process. This issue stems from insecure bootloader settings. By executing specific bootloader commands, an attacker may succeed in loading unverified software, which could compromise the integrity and security of the affected devices. Proper management of bootloader configurations is crucial to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cisco NX-OS Software 8.2(5)
Cisco NX-OS Software 7.3(5)D1(1)
Cisco NX-OS Software 8.4(2)
References
CVSS V3.1
Timeline
- ๐พ
Exploit known to exist
Vulnerability published