National Cyber Warfare Foundation (NCWF)

Hundred of CISCO switches impacted by bootloader flaw


0 user ratings
2024-12-06 01:07:57
milo
Blue Team (CND)

 - archive -- 
A bootloader vulnerability in Cisco NX-OS affects 100+ switches, allowing attackers to bypass image signature checks. Cisco released security patches for a vulnerability, tracked as CVE-2024-20397 (CVSS score of 5.2), in the NX-OS software’s bootloader that could be exploited by attackers to bypass image signature verification. “A vulnerability in the bootloader of Cisco NX-OS Software could […


A bootloader vulnerability in Cisco NX-OS affects 100+ switches, allowing attackers to bypass image signature checks.





Cisco released security patches for a vulnerability, tracked as CVE-2024-20397 (CVSS score of 5.2), in the NX-OS software’s bootloader that could be exploited by attackers to bypass image signature verification.





“A vulnerability in the bootloader of Cisco NX-OS Software could allow an unauthenticated attacker with physical access to an affected device, or an authenticated, local attacker with administrative credentials, to bypass NX-OS image signature verification.” reads the advisory.





The root cause of the vulnerability is insecure bootloader settings. An attacker could execute a series of bootloader commands to trigger the vulnerability. 





“A successful exploit could allow the attacker to bypass NX-OS image signature verification and load unverified software.” continues the advisory.





The vulnerability affects the following Cisco products running NX-OS Software with a vulnerable BIOS version, regardless of their configuration:









The IT giant states that there are no workarounds that address this vulnerability.





The company PSIRT is not aware of any attacks in the wild exploiting this vulnerability CVE-2024-20397





Cisco will not address the vulnerability for Nexus 92160YC-X that has reached the End of Vulnerability/Security Support.





Follow me on Twitter: @securityaffairs and Facebook and Mastodon





Pierluigi Paganini





(SecurityAffairs – hacking, NX-OS)



Source: SecurityAffairs
Source Link: https://securityaffairs.com/171729/security/cisco-switches-bootloader-flaw-cve-2024-20397.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)



Copyright 2012 through 2025 - National Cyber Warfare Foundation - All rights reserved worldwide.