EXECUTIVE SUMMARY
Multiple vulnerabilities have been identified in the IOS XR network operating system, with a total of eight flaws reported, six of which are categorized as high severity. The most critical issue, CVE-2024-20398, involves insufficient validation of user arguments passed to specific CLI commands, allowing attackers to potentially elevate their privileges. Attackers with low-privileged accounts could exploit this flaw to elevate privileges to root. CVE-2024-20304 is another significant vulnerability, allowing remote attackers to cause a denial-of-service (DoS) condition via crafted Mtrace2 packets. Two other high-severity vulnerabilities CVE-2024-20483 and CVE-2024-20489 impact the Routed Passive Optical Network (PON) controller software and could be used for command injection, potentially allowing attackers to retrieve MongoDB credentials or execute commands as root. Additionally, Cisco patched two other high-severity DoS flaws and two medium-severity vulnerabilities that could lead to file reading or service disruptions. There is no evidence that these vulnerabilities have been exploited in the wild.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
Multiple vulnerabilities have been identified in the IOS XR network operating system, with a total of eight flaws reported, six of which are categorized as high severity. The most critical issue, CVE-2024-20398, involves insufficient validation of user arguments passed to specific CLI commands, allowing attackers to potentially elevate their privileges. Attackers with low-privileged accounts could exploit this flaw to elevate privileges to root. CVE-2024-20304 is another significant vulnerability, allowing remote attackers to cause a denial-of-service (DoS) condition via crafted Mtrace2 packets. Two other high-severity vulnerabilities CVE-2024-20483 and CVE-2024-20489 impact the Routed Passive Optical Network (PON) controller software and could be used for command injection, potentially allowing attackers to retrieve MongoDB credentials or execute commands as root. Additionally, Cisco patched two other high-severity DoS flaws and two medium-severity vulnerabilities that could lead to file reading or service disruptions. There is no evidence that these vulnerabilities have been exploited in the wild.[emaillocker id="1283"]
Multiple high-severity vulnerabilities in IOS XR software have been addressed, including privilege escalation, DoS, and command injection issues. Though no active exploits have been reported, applying patches promptly is advised to reduce potential security risks.
RECOMMENDATION:
We strongly recommend you update Cisco IOS XR Software as below:
REFERENCES:
The following reports contain further technical details:
[/emaillocker]