Cisco NX-OS Software Vulnerability: Elevated Privileges with Authenticated Attack
CVE-2024-20284
8.8HIGH
Summary
An identified vulnerability in the Python interpreter of Cisco NX-OS Software allows an authenticated low-privileged local attacker to escape the confines of the Python sandbox. This breach stems from inadequate validation of user-supplied input. By carefully manipulating specific interpreter functions, an attacker could gain the ability to execute arbitrary commands directly on the device's underlying operating system, under the privileges of the authenticated user. It is crucial to note that exploitation of this vulnerability requires Python execution privileges, which are outlined in the official product documentation.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published