CVE-2024-20284

CWE-693CWE-6534 documents4 sources
Severity
8.8HIGH
EPSS
0.1%
top 71.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 28

Description

A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to escape the Python sandbox and gain unauthorized access to the underlying operating system of the device. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by manipulating specific functions within the Python interpreter. A successful exploit could allow an attacker to escape the Python sandbox and

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:LExploitability: 1.8 | Impact: 3.4

Affected Packages2 packages

CVEListV5cisco/cisco_nx-os_software320 versions+319
NVDcisco/nx-os9.3\(13\)

🔴Vulnerability Details

2
GHSA
GHSA-q35m-mgqf-ff28: A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to escape the Python sa2024-08-28
CVEList
Cisco NX-OS Software Python Parser Escape Vulnerability2024-08-28

📋Vendor Advisories

1
Cisco
Cisco NX-OS Software Python Sandbox Escape Vulnerabilities2024-08-28