Vulnslist

Cisco vulnerabilities by product, model, software, and advisory.

Multiple Cisco Products Web-Based Management Interface Privilege Escalation Vulnerability

cisco-sa-nso-auth-bypass-QnTEesp · High · Published · Updated

A vulnerability in the JSON-RPC API feature in Cisco Crosswork Network Services Orchestrator (NSO) and ConfD that is used by the web-based management interfaces of Cisco Optical Site Manager and Cisco RV340 Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to modify the configuration of an affected application or device.  This vulnerability is due to improper authorization checks on the API. An attacker with privileges sufficient to access the affected application or device could exploit this vulnerability by sending malicious requests to the JSON-RPC API. A successful exploit could allow the attacker to make unauthorized modifications to the configuration of the affected application or device, including creating new user accounts or elevating their own privileges on an affected system. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nso-auth-bypass-QnTEesp

Cisco advisory · CSAF JSON

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2024-20381
Cisco Bug IDsCSCwj26769, CSCwj31961, CSCwj32133
CVSS ScoreBase 8.8
Base 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:X/RL:X/RC:X
Product Names From Source
Cisco IOS XR Software, Cisco Small Business RV Series Router Firmware, Cisco Network Services Orchestrator, Cisco ConfD, Cisco IOS

Related Products

Product CVE Evidence
Cisco Small Business RV Series Router Firmware CVE-2024-20381 Cisco OpenVuln
Cisco Network Services Orchestrator CVE-2024-20381 Cisco OpenVuln
Cisco IOS XR Software CVE-2024-20381 Cisco OpenVuln
Cisco IOS CVE-2024-20381 Cisco OpenVuln
Cisco ConfD CVE-2024-20381 Cisco OpenVuln