Patch Now: Cisco Zero-Day Under Fire From Chinese APT
ID: a652fed6-d204-5e90-b896-454bb9bae2fa
STIX ID: report--a652fed6-d204-5e90-b896-454bb9bae2fa
Feed Name: Dark Reading
Date Published: 2024-07-02
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Cisco patched a command-line injection flaw (CVE-2024-20399, CVSS 6.0) in NX-OS that allows authenticated admin users to execute arbitrary root commands; Sygnia reports the China-backed APT Velvet Ant has actively exploited the bug to jailbreak the NX-OS CLI, deploy custom malware to compromised Nexus switches, and maintain persistence as part of a broader multiyear campaign—organizations are advised to apply Cisco updates, restrict admin access, enforce MFA/PAM, limit outbound connections from switches, and follow strong patch and password hygiene.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
