CVE Vulnerabilities

CVE-2024-20278

Incomplete List of Disallowed Inputs

Published: Mar 27, 2024 | Modified: Aug 01, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability in the NETCONF feature of Cisco IOS XE Software could allow an authenticated, remote attacker to elevate privileges to root on an affected device. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted input over NETCONF to an affected device. A successful exploit could allow the attacker to elevate privileges from Administrator to root.

Weakness

The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete, leading to resultant weaknesses.

Affected Software

Name Vendor Start Version End Version
Ios_xe Cisco 17.6.1 (including) 17.6.1 (including)
Ios_xe Cisco 17.6.1a (including) 17.6.1a (including)
Ios_xe Cisco 17.6.1w (including) 17.6.1w (including)
Ios_xe Cisco 17.6.1x (including) 17.6.1x (including)
Ios_xe Cisco 17.6.1y (including) 17.6.1y (including)
Ios_xe Cisco 17.6.1z (including) 17.6.1z (including)
Ios_xe Cisco 17.6.1z1 (including) 17.6.1z1 (including)
Ios_xe Cisco 17.6.2 (including) 17.6.2 (including)
Ios_xe Cisco 17.6.3 (including) 17.6.3 (including)
Ios_xe Cisco 17.6.3a (including) 17.6.3a (including)
Ios_xe Cisco 17.6.4 (including) 17.6.4 (including)
Ios_xe Cisco 17.6.5 (including) 17.6.5 (including)
Ios_xe Cisco 17.6.5a (including) 17.6.5a (including)
Ios_xe Cisco 17.6.6 (including) 17.6.6 (including)
Ios_xe Cisco 17.6.6a (including) 17.6.6a (including)
Ios_xe Cisco 17.7.1 (including) 17.7.1 (including)
Ios_xe Cisco 17.7.1a (including) 17.7.1a (including)
Ios_xe Cisco 17.7.1b (including) 17.7.1b (including)
Ios_xe Cisco 17.7.2 (including) 17.7.2 (including)
Ios_xe Cisco 17.8.1 (including) 17.8.1 (including)
Ios_xe Cisco 17.8.1a (including) 17.8.1a (including)
Ios_xe Cisco 17.9.1 (including) 17.9.1 (including)
Ios_xe Cisco 17.9.1a (including) 17.9.1a (including)
Ios_xe Cisco 17.9.1w (including) 17.9.1w (including)
Ios_xe Cisco 17.9.1x (including) 17.9.1x (including)
Ios_xe Cisco 17.9.1x1 (including) 17.9.1x1 (including)
Ios_xe Cisco 17.9.1y (including) 17.9.1y (including)
Ios_xe Cisco 17.9.1y1 (including) 17.9.1y1 (including)
Ios_xe Cisco 17.9.2 (including) 17.9.2 (including)
Ios_xe Cisco 17.9.2a (including) 17.9.2a (including)
Ios_xe Cisco 17.9.3 (including) 17.9.3 (including)
Ios_xe Cisco 17.9.3a (including) 17.9.3a (including)
Ios_xe Cisco 17.9.4 (including) 17.9.4 (including)
Ios_xe Cisco 17.9.4a (including) 17.9.4a (including)
Ios_xe Cisco 17.10.1 (including) 17.10.1 (including)
Ios_xe Cisco 17.10.1a (including) 17.10.1a (including)
Ios_xe Cisco 17.10.1b (including) 17.10.1b (including)
Ios_xe Cisco 17.11.1 (including) 17.11.1 (including)
Ios_xe Cisco 17.11.1a (including) 17.11.1a (including)
Ios_xe Cisco 17.11.99sw (including) 17.11.99sw (including)
Ios_xe Cisco 17.12.1 (including) 17.12.1 (including)
Ios_xe Cisco 17.12.1a (including) 17.12.1a (including)
Ios_xe Cisco 17.12.1w (including) 17.12.1w (including)

Potential Mitigations

References