CISA, FBI Warn of OS Command-Injection Vulnerabilities
ID: 1b5c5598-8d8f-581f-9dc3-4e8f81b32f67
STIX ID: report--1b5c5598-8d8f-581f-9dc3-4e8f81b32f67
Feed Name: Dark Reading
Threat Score
The CISA and FBI issued a Secure by Design alert warning that OS command-injection flaws remain prevalent and have been actively exploited—most recently CVE-2024-20399 in Cisco NX-OS by China-backed group Velvet Ant—and urging software and device vendors to eliminate such weaknesses through secure-by-design development, safer command functions, threat modeling, modern libraries, rigorous code review, and adversarial testing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
