PT-2024-5455 · Cisco · Cisco Secure Web Appliance+1
Lorenzo Grespan
·
Published
2024-07-17
·
Updated
2025-08-08
·
CVE-2024-20435
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco Secure Web Appliance versions (affected versions not specified)
Description
The issue is related to insufficient validation of user-supplied input for the Command Line Interface (CLI) of Cisco AsyncOS for Secure Web Appliance. This could allow an authenticated, local attacker to execute arbitrary commands and elevate privileges to root. An attacker would need at least guest credentials to exploit this vulnerability. The exploitation involves authenticating to the system and executing a crafted command on the affected device, which could then allow the attacker to execute arbitrary commands on the underlying operating system.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Asyncos
Cisco Secure Web Appliance