CVE-2024-20306
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the Unified Threat Defense (UTD) configuration CLI of Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying host operating system. To exploit this vulnerability, an attacker must have level 15 privileges on the affected device.
This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by submitting a crafted CLI command to an affected device. A successful exploit could allow the attacker to execute arbitrary commands as root on the underlying operating system.
Una vulnerabilidad en la CLI de configuración de Unified Threat Defense (UTD) del software Cisco IOS XE podría permitir que un atacante local autenticado ejecute comandos arbitrarios como root en el sistema operativo host subyacente. Para aprovechar esta vulnerabilidad, un atacante debe tener privilegios de nivel 15 en el dispositivo afectado. Esta vulnerabilidad se debe a una validación de entrada insuficiente. Un atacante podría aprovechar esta vulnerabilidad enviando un comando CLI manipulado a un dispositivo afectado. Un exploit exitoso podría permitir al atacante ejecutar comandos arbitrarios como root en el sistema operativo subyacente.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2023-11-08 CVE Reserved
- 2024-03-27 CVE Published
- 2024-03-28 EPSS Updated
- 2024-08-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-233: Improper Handling of Parameters
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-utd-cmd-JbL8KvHT |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Cisco IOS XE Software Search vendor "Cisco" for product "Cisco IOS XE Software" | 17.10.1 Search vendor "Cisco" for product "Cisco IOS XE Software" and version "17.10.1" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco IOS XE Software Search vendor "Cisco" for product "Cisco IOS XE Software" | 17.10.1 Search vendor "Cisco" for product "Cisco IOS XE Software" and version "17.10.1" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco IOS XE Software Search vendor "Cisco" for product "Cisco IOS XE Software" | 17.10.1 Search vendor "Cisco" for product "Cisco IOS XE Software" and version "17.10.1" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco IOS XE Software Search vendor "Cisco" for product "Cisco IOS XE Software" | 17.11.1 Search vendor "Cisco" for product "Cisco IOS XE Software" and version "17.11.1" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco IOS XE Software Search vendor "Cisco" for product "Cisco IOS XE Software" | 17.11.1 Search vendor "Cisco" for product "Cisco IOS XE Software" and version "17.11.1" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco IOS XE Software Search vendor "Cisco" for product "Cisco IOS XE Software" | 17.12.1 Search vendor "Cisco" for product "Cisco IOS XE Software" and version "17.12.1" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco IOS XE Software Search vendor "Cisco" for product "Cisco IOS XE Software" | 17.12.1 Search vendor "Cisco" for product "Cisco IOS XE Software" and version "17.12.1" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco IOS XE Software Search vendor "Cisco" for product "Cisco IOS XE Software" | 17.12.1 Search vendor "Cisco" for product "Cisco IOS XE Software" and version "17.12.1" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco IOS XE Software Search vendor "Cisco" for product "Cisco IOS XE Software" | 17.11.99 Search vendor "Cisco" for product "Cisco IOS XE Software" and version "17.11.99" | en |
Affected
|