Cisco NX-OS Software Vulnerability: Elevated Privileges with Authenticated Attack
CVE-2024-20284
8.8HIGH
What is CVE-2024-20284?
An identified vulnerability in the Python interpreter of Cisco NX-OS Software allows an authenticated low-privileged local attacker to escape the confines of the Python sandbox. This breach stems from inadequate validation of user-supplied input. By carefully manipulating specific interpreter functions, an attacker could gain the ability to execute arbitrary commands directly on the device's underlying operating system, under the privileges of the authenticated user. It is crucial to note that exploitation of this vulnerability requires Python execution privileges, which are outlined in the official product documentation.