PT-2024-3640 · Cisco · Cisco Crosswork Network Services Orchestrator

Elias Ikkelä-Koski

·

Published

2024-05-15

·

Updated

2024-05-15

·

CVE-2024-20366

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco Crosswork Network Services Orchestrator (NSO) (affected versions not specified)
Description A vulnerability in the Tail-f High Availability Cluster Communications (HCC) function pack could allow an authenticated, local attacker to elevate privileges to root on an affected device. This issue exists because a user-controlled search path is used to locate executable files, allowing an attacker to configure the application in a way that causes a malicious file to be executed. A successful exploit could allow the attacker to execute arbitrary code on an affected device as the root user. The attacker would need valid credentials on an affected device to exploit this vulnerability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

BDU:2024-03965
CVE-2024-20366

Affected Products

Cisco Crosswork Network Services Orchestrator