CVE-2020-3454 is a high-severity command injection vulnerability affecting the Call Home feature in Cisco NX-OS Software. An authenticated, remote attacker can exploit insufficient input validation in HTTP-configured Call Home parameters to execute arbitrary commands with root privileges on the underlying operating system. The CVSS score is 7.2 (HIGH), indicating a network attack vector with low complexity and high impact on confidentiality, integrity, and availability. While no public exploit code or active exploitation is reported, there is some community discussion and media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.