Cisco NX-OS Software Vulnerability Allows Low-Privileged Attackers to Escape Python Sandbox and Access Underlying OS
CVE-2024-20286
8.8HIGH
What is CVE-2024-20286?
A vulnerability in the Python interpreter of Cisco NX-OS Software poses risks to the security of devices running this software. It arises from inadequate validation of user-supplied input, allowing low-privileged, authenticated local attackers to potentially escape the Python sandbox. By manipulating specific functions within the interpreter, an attacker could execute arbitrary commands on the device's underlying operating system with the same privileges as the authenticated user. It is essential for users with Python execution privileges to review product-specific documentation for further details and security measures.