Cisco Security Advisory
Follow
Cisco NX-OS Software Command Injection Vulnerability
A vulnerability exists in the Cisco NX-OS Software CLI. This allows an authenticated, local attacker to perform command injection. Exploitation requires valid user credentials on the affected device. The vulnerability stems from insufficient validation of user-supplied input. Attackers can exploit it by providing crafted input to specific CLI commands. A successful exploit enables reading and writing files on the operating system. File system access is restricted by the privileges of a non-root user. Cisco has released software updates to fix this vulnerability. There are no available workarounds for this issue. The security impact rating for this vulnerability is Medium, identified as CVE-2025-20292.