CVE-2020-3454: Cisco NX-OS Software Call Home Command Injection Vulnerability
A vulnerability in the Call Home feature of Cisco NX-OS Software could allow an authenticated, remote attacker to inject arbitrary commands that could be executed with root privileges on the underlying operating system (OS). The vulnerability is due to insufficient input validation of specific Call Home configuration parameters when the software is configured for transport method HTTP. An attacker could exploit this vulnerability by modifying parameters within the Call Home configuration on an affected device. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the underlying OS.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-3454?
CVE-2020-3454 has a high severity rating due to its potential to allow unauthenticated remote command injection with root privileges.
How do I fix CVE-2020-3454?
To address CVE-2020-3454, apply the latest security patches and updates provided by Cisco for affected NX-OS versions.
What vulnerabilities are associated with CVE-2020-3454?
CVE-2020-3454 allows command injection due to insufficient input validation in the Call Home feature of Cisco NX-OS.
Who is affected by CVE-2020-3454?
CVE-2020-3454 affects devices running vulnerable versions of Cisco NX-OS Software.
Can CVE-2020-3454 be exploited remotely?
Yes, CVE-2020-3454 can be exploited by an authenticated remote attacker.