Cisco warns of NX-OS zero-day exploited to deploy custom malware
ID: 2611cbfa-6d13-56d4-964e-af25a7e41072
STIX ID: report--2611cbfa-6d13-56d4-964e-af25a7e41072
Feed Name: Bleeping Computer
Cisco patched a NX-OS zero-day (CVE-2024-20399) that was exploited in April by a state-sponsored group tracked as Velvet Ant to gain administrator-level access to Nexus and MDS switches and install custom root-level malware enabling remote command execution and stealthy persistence; affected device families include MDS 9000 and Nexus 3000/5500/5600/6000/7000/9000 series. Cisco recommends monitoring and rotating network-admin and vdc-admin credentials and using the Cisco Software Checker to identify exposed devices; the report also references related state-backed campaigns exploiting other Cisco and F5 zero-days.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
