Cisco IOS XR是美国思科(Cisco)公司的一套为其网络设备开发的操作系统。 Cisco IOS XR存在安全漏洞,该漏洞源于该软件在思科 IOS XR 软件支持的硬件上作为 Docker 容器运行,可能允许经过身份验证的远程攻击者在 PON 管理器上拥有管理员级权限或直接访问 PON 管理器 MongoDB 实例,从而对 PON 控制器容器执行命令注入攻击并以root身份执行任意命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Cisco | Cisco IOS XR Software | 24.1.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-20381 | 8.8 HIGH | Cisco Network Services Orchestrator Configuration Update Authorization Bypass Vulnerabilit |
| CVE-2024-20398 | 8.8 HIGH | Cisco IOS XR Software Local Privilege Escalation Vulnerability |
| CVE-2024-20304 | 8.6 HIGH | Cisco IOS XR Software Packet Memory Exhaustion Vulnerability |
| CVE-2024-20489 | 8.4 HIGH | Cisco Routed Passive Optical Network Cleartext Password Vulnerability |
| CVE-2024-20406 | 7.4 HIGH | Cisco IOS XR Software Intermediate System-to-Intermediate System Denial of Service Vulnera |
| CVE-2024-20317 | 7.4 HIGH | Cisco IOS XR Software Layer 2 Services Denial of Service Vulnerability |
| CVE-2024-20343 | 5.5 MEDIUM | Cisco IOS XR Software CLI Arbitrary File Read Vulnerability |
| CVE-2024-20390 | 5.3 MEDIUM | Cisco IOS XR Software Dedicated XML Agent TCP Denial of Service Vulnerability |
No comments yet