PT-2024-7097 · Cisco · Cisco Routed Pon Controller+1
James Spadaro
·
Published
2024-09-11
·
Updated
2024-10-03
·
CVE-2024-20483
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco Routed PON Controller Software (affected versions not specified)
Description
The issue exists due to insufficient validation of arguments passed to specific configuration commands, allowing an authenticated, remote attacker with Administrator-level privileges on the PON Manager or direct access to the PON Manager MongoDB instance to perform command injection attacks on the PON Controller container and execute arbitrary commands as root. An attacker could exploit these vulnerabilities by including crafted input as the argument of an affected configuration command.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Ios Xr
Cisco Routed Pon Controller