PT-2024-3640 · Cisco · Cisco Crosswork Network Services Orchestrator
Elias Ikkelä-Koski
·
Published
2024-05-15
·
Updated
2024-05-15
·
CVE-2024-20366
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco Crosswork Network Services Orchestrator (NSO) (affected versions not specified)
Description
A vulnerability in the Tail-f High Availability Cluster Communications (HCC) function pack could allow an authenticated, local attacker to elevate privileges to root on an affected device. This issue exists because a user-controlled search path is used to locate executable files, allowing an attacker to configure the application in a way that causes a malicious file to be executed. A successful exploit could allow the attacker to execute arbitrary code on an affected device as the root user. The attacker would need valid credentials on an affected device to exploit this vulnerability.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Crosswork Network Services Orchestrator