logo

Cisco warns of NX-OS zero-day exploited to deploy custom malware

ID: 2611cbfa-6d13-56d4-964e-af25a7e41072

STIX ID: report--2611cbfa-6d13-56d4-964e-af25a7e41072

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2024-07-01

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Cisco patched a NX-OS zero-day (CVE-2024-20399) that was exploited in April by a state-sponsored group tracked as Velvet Ant to gain administrator-level access to Nexus and MDS switches and install custom root-level malware enabling remote command execution and stealthy persistence; affected device families include MDS 9000 and Nexus 3000/5500/5600/6000/7000/9000 series. Cisco recommends monitoring and rotating network-admin and vdc-admin credentials and using the Cisco Software Checker to identify exposed devices; the report also references related state-backed campaigns exploiting other Cisco and F5 zero-days.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.