logo

CISA, FBI Warn of OS Command-Injection Vulnerabilities

ID: 1b5c5598-8d8f-581f-9dc3-4e8f81b32f67

STIX ID: report--1b5c5598-8d8f-581f-9dc3-4e8f81b32f67

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2024-07-12

Date Updated: 2026-05-05

Author: Dark Reading Staff

...
...

The CISA and FBI issued a Secure by Design alert warning that OS command-injection flaws remain prevalent and have been actively exploited—most recently CVE-2024-20399 in Cisco NX-OS by China-backed group Velvet Ant—and urging software and device vendors to eliminate such weaknesses through secure-by-design development, safer command functions, threat modeling, modern libraries, rigorous code review, and adversarial testing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.