cbcvebase.
CVE-2024-20381
published 2024-09-11

CVE-2024-20381: A vulnerability in the JSON-RPC API feature in Cisco Crosswork Network Services Orchestrator (NSO) and ConfD that is used by the web-based management…

PriorityP261high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.58%
43.7th percentile
A vulnerability in the JSON-RPC API feature in Cisco Crosswork Network Services Orchestrator (NSO) and ConfD that is used by the web-based management interfaces of Cisco Optical Site Manager and Cisco RV340 Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to modify the configuration of an affected application or device. This vulnerability is due to improper authorization checks on the API. An attacker with privileges sufficient to access the affected application or device could exploit this vulnerability by sending malicious requests to the JSON-RPC API. A successful exploit could allow the attacker to make unauthorized modifications to the configuration of the affected application or device, including creating new user accounts or elevating their own privileges on an affected system.

Affected

543 ranges· showing 25
VendorProductVersion rangeFixed in
ciscocisco_ios_xr_software
ciscocisco_ios_xr_software
ciscocisco_ios_xr_software
ciscocisco_ios_xr_software
ciscocisco_ios_xr_software
ciscocisco_ios_xr_software
ciscocisco_ios_xr_software
ciscocisco_ios_xr_software
ciscocisco_ios_xr_software
ciscocisco_ios_xr_software
ciscocisco_ios_xr_software
ciscocisco_ios_xr_software
ciscocisco_ios_xr_software
ciscocisco_ios_xr_software
ciscocisco_ios_xr_software
ciscocisco_ios_xr_software
ciscocisco_ios_xr_software
ciscocisco_ios_xr_software
ciscocisco_ios_xr_software
ciscocisco_ios_xr_software
ciscocisco_ios_xr_software
ciscocisco_ios_xr_software
ciscocisco_ios_xr_software
ciscocisco_ios_xr_software
ciscocisco_ios_xr_software

Detection & IOCsextracted from sources · hover to see the quote

  • Monitor for malicious requests targeting the JSON-RPC API endpoint of affected Cisco products (NSO, ConfD, Optical Site Manager, RV340 routers), particularly from authenticated users attempting unauthorized configuration changes such as creating new user accounts or elevating privileges.
  • Alert on unexpected privilege escalation or new user account creation via the web-based management interface of Cisco Crosswork NSO, ConfD, Optical Site Manager, or RV340 routers, as these are the primary post-exploitation outcomes.
  • ·The vulnerability is due to improper authorization checks on the JSON-RPC API; exploitation requires an already-authenticated attacker with at least some level of access to the affected device or application (not unauthenticated).
  • ·There are no workarounds available; the only remediation is applying the software updates released by Cisco. Affected products include Cisco Crosswork NSO, ConfD, Optical Site Manager, and RV340 Dual WAN Gigabit VPN Routers.
  • ·Tracked under Cisco Bug IDs CSCwj26769, CSCwj31961, and CSCwj32133, covering multiple affected product lines.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_cisco8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.