VDB
CVE-2024-20262
CVE-2024-20262
PUBLISHED
Es besteht eine Schwachstelle in Cisco IOS XR. Dieser Fehler besteht im Secure Copy Protocol (SCP) und der SFTP-Funktion aufgrund einer fehlenden Validierung der SCP- und SFTP-CLI-Eingabeparameter. Ein lokaler Angreifer kann diese Schwachstelle ausnutzen, indem er sich am Gerät authentifiziert und SCP- oder SFTP-CLI-Befehle mit bestimmten Parametern ausgibt, um einen Denial-of-Service-Zustand zu verursachen.
EPSS 0.02% · 6.6th percentile
Risk Scores
EPSS Score
0.02%
6.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Cisco IOS XR <7.9.21 | |
| Cisco | Cisco IOS XR <7.9.2 | |
| Cisco | Cisco IOS XR <7.11.1 | |
| Cisco | Cisco IOS XR <7.10.2 | |
| Cisco | Cisco IOS XR <7.10.1 | |
| Cisco | Cisco IOS XR <24.1.1 |
Exploit Intelligence
- CIRCL seen: CVE-2024-20262 (circl-sighting)
- CIRCL seen: CVE-2024-20262 (circl-sighting)
- cisco-sa-iosxr-scp-dos-kb6sUUHw (circl)
Timeline
- Mar 13, 2024 CVE Published
- Mar 13, 2024 PoC Published
- Mar 13, 2024 PoC Published
- Mar 14, 2024 EPSS Score
- Apr 9, 2024 EPSS Score
- May 5, 2024 EPSS Score
- May 31, 2024 EPSS Score
- Jun 27, 2024 EPSS Score
- Jul 23, 2024 EPSS Score
- Aug 1, 2024 CVE Updated
- Aug 18, 2024 EPSS Score
- Sep 13, 2024 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-0631.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-0631 advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-acl-bypass-RZU5NL3e advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-dhcp-dos-3tgPKRdm advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-pppma-JKWFgneW advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-scp-dos-kb6sUUHw advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-ssh-privesc-eWDMKew3 advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snmp-uhv6ZDeF advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-xrl2vpn-jesrU3fc advisory