Hundred of CISCO switches impacted by bootloader flaw

Share:

A bootloader vulnerability in Cisco NX-OS affects 100+ switches, allowing attackers to bypass image signature checks.

Cisco released security patches for a vulnerability, tracked as CVE-2024-20397 (CVSS score of 5.2), in the NX-OS software’s bootloader that could be exploited by attackers to bypass image signature verification.

“A vulnerability in the bootloader of Cisco NX-OS Software could allow an unauthenticated attacker with physical access to an affected device, or an authenticated, local attacker with administrative credentials, to bypass NX-OS image signature verification.” reads the advisory.

The root cause of the vulnerability is insecure bootloader settings. An attacker could execute a series of bootloader commands to trigger the vulnerability.

“A successful exploit could allow the attacker to bypass NX-OS image signature verification and load unverified software.” continues the advisory.

The vulnerability affects the following Cisco products running NX-OS Software with a vulnerable BIOS version, regardless of their configuration:

  • UCS 6500 Series Fabric Interconnects (CSCwj35846)
  • MDS 9000 Series Multilayer Switches (CSCwh76163)
  • Nexus 3000 Series Switches (CSCwm47438)
  • Nexus 7000 Series Switches (CSCwh76166)
  • Nexus 9000 Series Fabric Switches in ACI mode (CSCwn11901)
  • Nexus 9000 Series Switches in standalone NX-OS mode (CSCwm47438)
  • UCS 6400 Series Fabric Interconnects (CSCwj35846)

The IT giant states that there are no workarounds that address this vulnerability.

The company PSIRT is not aware of any attacks in the wild exploiting this vulnerability CVE-2024-20397

Cisco will not address the vulnerability for Nexus 92160YC-X that has reached the End of Vulnerability/Security Support.

Source

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
11:07 pm, Jun 14, 2025
weather icon 16°C
L: 14° | H: 17°
overcast clouds
Humidity: 72 %
Pressure: 1019 mb
Wind: 11 mph SW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 88%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:42 am
Sunset: 9:18 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 10:00 pm
weather icon
14° | 17°°C 0.2 mm 20% 12 mph 82 % 1025 mb 0 mm/h
Mon Jun 16 10:00 pm
weather icon
14° | 25°°C 0 mm 0% 6 mph 87 % 1028 mb 0 mm/h
Tue Jun 17 10:00 pm
weather icon
16° | 27°°C 0 mm 0% 9 mph 79 % 1027 mb 0 mm/h
Wed Jun 18 10:00 pm
weather icon
17° | 27°°C 0 mm 0% 10 mph 80 % 1026 mb 0 mm/h
Thu Jun 19 10:00 pm
weather icon
16° | 24°°C 0 mm 0% 11 mph 76 % 1027 mb 0 mm/h
Tomorrow 1:00 am
weather icon
15° | 16°°C 0 mm 0% 6 mph 75 % 1019 mb 0 mm/h
Tomorrow 4:00 am
weather icon
12° | 14°°C 0 mm 0% 6 mph 82 % 1020 mb 0 mm/h
Tomorrow 7:00 am
weather icon
14° | 14°°C 0 mm 0% 8 mph 75 % 1021 mb 0 mm/h
Tomorrow 10:00 am
weather icon
20° | 20°°C 0 mm 0% 10 mph 64 % 1022 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
21° | 21°°C 0.2 mm 20% 10 mph 52 % 1022 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
23° | 23°°C 0 mm 0% 12 mph 36 % 1022 mb 0 mm/h
Tomorrow 7:00 pm
weather icon
21° | 21°°C 0 mm 0% 10 mph 52 % 1023 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
17° | 17°°C 0.2 mm 20% 7 mph 79 % 1025 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€91,177.07
-0.32%
Ethereum(ETH)
€2,189.40
-1.01%
Tether(USDT)
€0.87
-0.01%
XRP(XRP)
€1.85
-0.22%
Solana(SOL)
€125.02
-1.91%
USDC(USDC)
€0.87
-0.01%
Dogecoin(DOGE)
€0.154175
-0.43%
Shiba Inu(SHIB)
€0.000010
0.26%
Pepe(PEPE)
€0.000010
-1.76%
Scroll to Top