PT-2024-4292 · Cisco · Cisco Crosswork Network Services Orchestrator

Published

2024-05-16

·

Updated

2024-05-16

·

CVE-2024-20389

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco Crosswork Network Services Orchestrator (affected versions not specified) ConfD (affected versions not specified)
Description A vulnerability in the ConfD CLI and the Cisco Crosswork Network Services Orchestrator CLI is related to improper authorization enforcement when specific CLI commands are used. This could allow an authenticated, low-privileged, local attacker to read and write arbitrary files as root on the underlying operating system. An attacker could exploit this vulnerability by executing an affected CLI command with crafted arguments.
Recommendations As a temporary workaround, consider disabling the affected CLI commands until a patch is available. Restrict access to the ConfD CLI and the Cisco Crosswork Network Services Orchestrator CLI to minimize the risk of exploitation. Avoid using crafted arguments in CLI commands until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-04779
CVE-2024-20389

Affected Products

Cisco Crosswork Network Services Orchestrator