PT-2024-7097 · Cisco · Cisco Routed Pon Controller+1

James Spadaro

·

Published

2024-09-11

·

Updated

2024-10-03

·

CVE-2024-20483

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco Routed PON Controller Software (affected versions not specified)
Description The issue exists due to insufficient validation of arguments passed to specific configuration commands, allowing an authenticated, remote attacker with Administrator-level privileges on the PON Manager or direct access to the PON Manager MongoDB instance to perform command injection attacks on the PON Controller container and execute arbitrary commands as root. An attacker could exploit these vulnerabilities by including crafted input as the argument of an affected configuration command.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2024-08364
CVE-2024-20483

Affected Products

Cisco Ios Xr
Cisco Routed Pon Controller