Cisco IOS XR Software Vulnerability Could Lead to Elevated Privileges
CVE-2024-20320

7.8HIGH

Key Information:

Vendor
Cisco
Vendor
CVE Published:
13 March 2024

Summary

A vulnerability exists within the SSH client feature of Cisco IOS XR Software that affects various models of Cisco routers. This issue arises from inadequate validation of arguments provided with SSH client CLI commands. An attacker with low privileges on an affected device can exploit this vulnerability by executing a specifically crafted SSH client command. If successful, this can lead to unauthorized elevation of their privileges to root access on the device, potentially allowing them to manipulate sensitive configurations and compromise the integrity of network operations.

Affected Version(s)

Cisco IOS XR Software 7.2.1

Cisco IOS XR Software 7.2.2

Cisco IOS XR Software 7.3.1

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.