Cisco IOS XE Software Vulnerability: Remote CSRF Execution
CVE-2024-20437

8.8HIGH

Key Information:

Vendor
Cisco
Status
Vendor
CVE Published:
25 September 2024

Summary

A vulnerability in the web-based management interface of Cisco IOS XE Software allows remote attackers to exploit cross-site request forgery (CSRF) weaknesses. This condition arises from inadequate protections against CSRF, enabling an attacker to pose as an authenticated user. By convincing a targeted user to click on a specially crafted link, attackers can execute commands on the command line interface (CLI) of the affected device, taking actions with the same privileges as the authenticated user. Organizations utilizing Cisco IOS XE Software should take immediate precautions to mitigate potential risks associated with this vulnerability.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.