Cisco IOS XR Software Vulnerability Could Allow Access to MongoDB Credentials
CVE-2024-20489
What is CVE-2024-20489?
A vulnerability in the storage method of the PON Controller configuration file could allow an authenticated, local attacker with low privileges to obtain the MongoDB credentials.
This vulnerability is due to improper storage of the unencrypted database credentials on the device that is running Cisco IOS XR Software. An attacker could exploit this vulnerability by accessing the configuration files on an affected system. A successful exploit could allow the attacker to view MongoDB credentials.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cisco IOS XR Software 24.1.1
Cisco IOS XR Software 24.2.1
Cisco IOS XR Software 24.1.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved