CVE-2024-20398

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Sep 11, 2024
Updated: Sep 12, 2024
CWE ID 78

Summary

CVE-2024-20398 is a vulnerability in the Command Line Interface (CLI) of Cisco IOS XR Software that allows an authenticated local attacker to gain read/write access to the file system of affected devices. This issue arises from inadequate validation of user arguments in specific CLI commands, enabling attackers with low-level privileges to execute crafted commands and potentially escalate their privileges to root. The vulnerability poses a high risk, with a base severity score of 8.8, as it can significantly impact confidentiality, integrity, and availability. Affected products include various versions of Cisco IOS XR Software across numerous device models. Organizations are advised to apply relevant patches provided by Cisco to remediate this vulnerability effectively.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share