Cisco NX-OS Software Vulnerability Allows Low-Privileged Attackers to Escape Python Sandbox and Access Underlying OS
CVE-2024-20286
8.8HIGH
Summary
A vulnerability in the Python interpreter of Cisco NX-OS Software poses risks to the security of devices running this software. It arises from inadequate validation of user-supplied input, allowing low-privileged, authenticated local attackers to potentially escape the Python sandbox. By manipulating specific functions within the interpreter, an attacker could execute arbitrary commands on the device's underlying operating system with the same privileges as the authenticated user. It is essential for users with Python execution privileges to review product-specific documentation for further details and security measures.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published