Cisco NX-OS Software Vulnerability: Elevated Privileges with Authenticated Attack
CVE-2024-20284

8.8HIGH

Key Information:

Vendor
Cisco
Status
Vendor
CVE Published:
28 August 2024

Summary

An identified vulnerability in the Python interpreter of Cisco NX-OS Software allows an authenticated low-privileged local attacker to escape the confines of the Python sandbox. This breach stems from inadequate validation of user-supplied input. By carefully manipulating specific interpreter functions, an attacker could gain the ability to execute arbitrary commands directly on the device's underlying operating system, under the privileges of the authenticated user. It is crucial to note that exploitation of this vulnerability requires Python execution privileges, which are outlined in the official product documentation.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

.