Hunderte von CISCO-Switches sind von Bootloader-Fehler betroffen

Teilen:

A bootloader vulnerability in Cisco NX-OS affects 100+ switches, allowing attackers to bypass image signature checks.

Cisco released security patches for a vulnerability, tracked as CVE-2024-20397 (CVSS score of 5.2), in the NX-OS software’s bootloader that could be exploited by attackers to bypass image signature verification.

“A vulnerability in the bootloader of Cisco NX-OS Software could allow an unauthenticated attacker with physical access to an affected device, or an authenticated, local attacker with administrative credentials, to bypass NX-OS image signature verification.” reads the advisory.

The root cause of the vulnerability is insecure bootloader settings. An attacker could execute a series of bootloader commands to trigger the vulnerability.

“A successful exploit could allow the attacker to bypass NX-OS image signature verification and load unverified software.” continues the advisory.

The vulnerability affects the following Cisco products running NX-OS Software with a vulnerable BIOS version, regardless of their configuration:

  • UCS 6500 Series Fabric Interconnects (CSCwj35846)
  • MDS 9000 Series Multilayer Switches (CSCwh76163)
  • Nexus 3000 Series Switches (CSCwm47438)
  • Nexus 7000 Series Switches (CSCwh76166)
  • Nexus 9000 Series Fabric Switches in ACI mode (CSCwn11901)
  • Nexus 9000 Series Switches in standalone NX-OS mode (CSCwm47438)
  • UCS 6400 Series Fabric Interconnects (CSCwj35846)

The IT giant states that there are no workarounds that address this vulnerability.

The company PSIRT is not aware of any attacks in the wild exploiting this vulnerability CVE-2024-20397

Cisco will not address the vulnerability for Nexus 92160YC-X that has reached the End of Vulnerability/Security Support.

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
10:29 am, Mai 17, 2025
Wetter-Symbol 14°C
L: 13° | H: 15°
wenige Wolken
Luftfeuchtigkeit: 64 %
Druck: 1023 mb
Wind: 4 mph NE
Windböe: 10 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 11%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 5:05 am
Sonnenuntergang: 8:48 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
13° | 15°°C 0 mm 0% 9 mph 69 % 1023 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
9° | 16°°C 0 mm 0% 9 mph 83 % 1022 mb 0 mm/h
Mo. Mai 19 10:00 pm
Wetter-Symbol
9° | 20°°C 0 mm 0% 11 mph 90 % 1022 mb 0 mm/h
Di. Mai 20 10:00 pm
Wetter-Symbol
11° | 22°°C 0 mm 0% 9 mph 66 % 1022 mb 0 mm/h
Mi. Mai 21 10:00 pm
Wetter-Symbol
12° | 18°°C 1 mm 100% 7 mph 70 % 1020 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
15° | 16°°C 0 mm 0% 7 mph 58 % 1023 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
18° | 19°°C 0 mm 0% 8 mph 46 % 1022 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
18° | 18°°C 0 mm 0% 9 mph 45 % 1021 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
13° | 13°°C 0 mm 0% 7 mph 69 % 1022 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
11° | 11°°C 0 mm 0% 5 mph 75 % 1022 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
9° | 9°°C 0 mm 0% 6 mph 80 % 1022 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
9° | 9°°C 0 mm 0% 8 mph 83 % 1022 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
11° | 11°°C 0 mm 0% 7 mph 70 % 1022 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€92,496.27
-0.27%
Ethereum(ETH)
€2,222.36
-4.34%
Fesseln(USDT)
€0.90
0.00%
XRP(XRP)
€2.12
-1.47%
Solana(SOL)
€150.64
-1.60%
USDC(USDC)
€0.90
0.00%
Dogecoin(DOGE)
€0.193245
-4.12%
Shiba Inu(SHIB)
€0.000013
-5.01%
Pepe(PEPE)
€0.000011
-7.62%
Peanut das Eichhörnchen(PNUT)
€0.257741
-15.98%
Nach oben scrollen