CVE-2025-20161 - CVE House
Back to Database
Status published Medium CVE-2025-20161

Cisco NX-OS Software Command Injection Vulnerability

Vulnerability Description

A vulnerability in the software upgrade process of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an authenticated, local attacker with valid Administrator credentials to execute a command injection attack on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of specific elements within a software image. An attacker could exploit this vulnerability by installing a crafted image. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with root privileges.  Note: Administrators should validate the hash of any software image before installation.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-20161

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Cisco NX-OS Software
Vulnerable Versions:
9.2(3), 7.0(3)I5(2), 6.0(2)A8(7a), 7.0(3)I4(5), 7.0(3)I4(6), 7.0(3)I4(3), 9.2(2v), 7.0(3)I4(7), 7.0(3)I4(1), 7.0(3)I4(8), 7.0(3)I4(2), 6.0(2)A8(11), 9.2(1), 9.2(2t), 9.2(3y), 7.0(3)I4(1t), 7.0(3)I7(6z), 9.3(2), 7.0(3)F3(3), 7.0(3)I7(3z), 7.0(3)IM7(2), 6.0(2)A8(11b), 7.0(3)I7(5a), 7.0(3)I6(1), 7.0(3)I5(3b), 9.2(4), 6.0(2)A8(10), 6.0(2)A8(2), 7.0(3)IC4(4), 7.0(3)F3(3c), 7.0(3)F3(1), 7.0(3)F3(5), 7.0(3)I7(2), 7.0(3)I5(3), 7.0(3)I7(3), 6.0(2)A8(6), 7.0(3)I6(2), 6.0(2)A8(5), 9.3(1), 6.0(2)A8(7), 7.0(3)I7(6), 6.0(2)A8(11a), 7.0(3)I4(8z), 7.0(3)I4(9), 7.0(3)I7(4), 7.0(3)I7(7), 6.0(2)A8(9), 6.0(2)A8(1), 6.0(2)A8(10a), 7.0(3)I5(1), 9.3(1z), 9.2(2), 7.0(3)F3(4), 7.0(3)I4(8b), 6.0(2)A8(3), 7.0(3)I4(6t), 7.0(3)I5(3a), 6.0(2)A8(8), 7.0(3)I7(5), 7.0(3)F3(3a), 6.0(2)A8(4), 7.0(3)I4(8a), 7.0(3)F3(2), 7.0(3)I4(4), 7.0(3)I7(1), 7.0(3)IA7(2), 7.0(3)IA7(1), 6.0(2)A8(7b), 6.0(2)A8(4a), 9.3(3), 7.0(3)I7(8), 9.3(4), 9.3(5), 7.0(3)I7(9), 9.3(6), 10.1(2), 10.1(1), 9.3(5w), 9.3(7), 9.3(7k), 7.0(3)I7(9w), 10.2(1), 9.3(7a), 9.3(8), 7.0(3)I7(10), 10.2(1q), 10.2(2), 9.3(9), 10.1(2t), 10.2(3), 10.2(3t), 9.3(10), 10.2(2a), 10.3(1), 10.2(4), 10.3(2), 9.3(11), 10.3(3), 10.2(5), 9.3(12), 10.2(3v), 10.4(1), 10.3(99w), 10.2(6), 10.3(3w), 10.3(99x), 10.3(3o), 10.3(4), 10.3(3p), 10.3(4a), 10.4(2), 10.3(3q), 9.3(13), 10.3(5), 10.2(7), 10.4(3), 10.3(3x), 10.3(4g), 10.5(1), 10.2(8), 10.3(3r), 10.3(6), 9.3(14), 10.3(4h)

Timeline

Official Publish: February 26th, 2025
Last Modified: February 27th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N

Weaknesses (CWE)