CVE Vulnerabilities

CVE-2024-20414

Improper Authorization

Published: Sep 25, 2024 | Modified: Oct 02, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A vulnerability in the web UI feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system through the web UI. This vulnerability is due to incorrectly accepting configuration changes through the HTTP GET method. An attacker could exploit this vulnerability by persuading a currently authenticated administrator to follow a crafted link. A successful exploit could allow the attacker to change the configuration of the affected device.

Weakness

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Affected Software

NameVendorStart VersionEnd Version
Ios_xeCisco3.2.0se (including)3.2.0se (including)
Ios_xeCisco3.2.0sg (including)3.2.0sg (including)
Ios_xeCisco3.2.1se (including)3.2.1se (including)
Ios_xeCisco3.2.1sg (including)3.2.1sg (including)
Ios_xeCisco3.2.2se (including)3.2.2se (including)
Ios_xeCisco3.2.2sg (including)3.2.2sg (including)
Ios_xeCisco3.2.3se (including)3.2.3se (including)
Ios_xeCisco3.2.3sg (including)3.2.3sg (including)
Ios_xeCisco3.2.4sg (including)3.2.4sg (including)
Ios_xeCisco3.2.5sg (including)3.2.5sg (including)
Ios_xeCisco3.2.6sg (including)3.2.6sg (including)
Ios_xeCisco3.2.7sg (including)3.2.7sg (including)
Ios_xeCisco3.2.8sg (including)3.2.8sg (including)
Ios_xeCisco3.2.9sg (including)3.2.9sg (including)
Ios_xeCisco3.2.10sg (including)3.2.10sg (including)
Ios_xeCisco3.2.11sg (including)3.2.11sg (including)
Ios_xeCisco3.3.0se (including)3.3.0se (including)
Ios_xeCisco3.3.0sg (including)3.3.0sg (including)
Ios_xeCisco3.3.0sq (including)3.3.0sq (including)
Ios_xeCisco3.3.1se (including)3.3.1se (including)
Ios_xeCisco3.3.1sg (including)3.3.1sg (including)
Ios_xeCisco3.3.1sq (including)3.3.1sq (including)
Ios_xeCisco3.3.2se (including)3.3.2se (including)
Ios_xeCisco3.3.2sg (including)3.3.2sg (including)
Ios_xeCisco3.3.3se (including)3.3.3se (including)
Ios_xeCisco3.3.4se (including)3.3.4se (including)
Ios_xeCisco3.3.5se (including)3.3.5se (including)
Ios_xeCisco3.4.0sg (including)3.4.0sg (including)
Ios_xeCisco3.4.0sq (including)3.4.0sq (including)
Ios_xeCisco3.4.1sg (including)3.4.1sg (including)
Ios_xeCisco3.4.1sq (including)3.4.1sq (including)
Ios_xeCisco3.4.2sg (including)3.4.2sg (including)
Ios_xeCisco3.4.3sg (including)3.4.3sg (including)
Ios_xeCisco3.4.4sg (including)3.4.4sg (including)
Ios_xeCisco3.4.5sg (including)3.4.5sg (including)
Ios_xeCisco3.4.6sg (including)3.4.6sg (including)
Ios_xeCisco3.4.7sg (including)3.4.7sg (including)
Ios_xeCisco3.4.8sg (including)3.4.8sg (including)
Ios_xeCisco3.5.0e (including)3.5.0e (including)
Ios_xeCisco3.5.0sq (including)3.5.0sq (including)
Ios_xeCisco3.5.1e (including)3.5.1e (including)
Ios_xeCisco3.5.1sq (including)3.5.1sq (including)
Ios_xeCisco3.5.2e (including)3.5.2e (including)
Ios_xeCisco3.5.2sq (including)3.5.2sq (including)
Ios_xeCisco3.5.3e (including)3.5.3e (including)
Ios_xeCisco3.5.3sq (including)3.5.3sq (including)
Ios_xeCisco3.5.4sq (including)3.5.4sq (including)
Ios_xeCisco3.5.5sq (including)3.5.5sq (including)
Ios_xeCisco3.5.6sq (including)3.5.6sq (including)
Ios_xeCisco3.5.7sq (including)3.5.7sq (including)
Ios_xeCisco3.5.8sq (including)3.5.8sq (including)
Ios_xeCisco3.6.0e (including)3.6.0e (including)
Ios_xeCisco3.6.1e (including)3.6.1e (including)
Ios_xeCisco3.6.2ae (including)3.6.2ae (including)
Ios_xeCisco3.6.2e (including)3.6.2e (including)
Ios_xeCisco3.6.3e (including)3.6.3e (including)
Ios_xeCisco3.6.4e (including)3.6.4e (including)
Ios_xeCisco3.6.5ae (including)3.6.5ae (including)
Ios_xeCisco3.6.5be (including)3.6.5be (including)
Ios_xeCisco3.6.5e (including)3.6.5e (including)
Ios_xeCisco3.6.6e (including)3.6.6e (including)
Ios_xeCisco3.6.7be (including)3.6.7be (including)
Ios_xeCisco3.6.7e (including)3.6.7e (including)
Ios_xeCisco3.6.8e (including)3.6.8e (including)
Ios_xeCisco3.6.9e (including)3.6.9e (including)
Ios_xeCisco3.6.10e (including)3.6.10e (including)
Ios_xeCisco3.7.0bs (including)3.7.0bs (including)
Ios_xeCisco3.7.0e (including)3.7.0e (including)
Ios_xeCisco3.7.0s (including)3.7.0s (including)
Ios_xeCisco3.7.1as (including)3.7.1as (including)
Ios_xeCisco3.7.1e (including)3.7.1e (including)
Ios_xeCisco3.7.1s (including)3.7.1s (including)
Ios_xeCisco3.7.2e (including)3.7.2e (including)
Ios_xeCisco3.7.2s (including)3.7.2s (including)
Ios_xeCisco3.7.2ts (including)3.7.2ts (including)
Ios_xeCisco3.7.3e (including)3.7.3e (including)
Ios_xeCisco3.7.3s (including)3.7.3s (including)
Ios_xeCisco3.7.4as (including)3.7.4as (including)
Ios_xeCisco3.7.4e (including)3.7.4e (including)
Ios_xeCisco3.7.4s (including)3.7.4s (including)
Ios_xeCisco3.7.5e (including)3.7.5e (including)
Ios_xeCisco3.7.5s (including)3.7.5s (including)
Ios_xeCisco3.7.6s (including)3.7.6s (including)
Ios_xeCisco3.7.7s (including)3.7.7s (including)
Ios_xeCisco3.8.0e (including)3.8.0e (including)
Ios_xeCisco3.8.0s (including)3.8.0s (including)
Ios_xeCisco3.8.1e (including)3.8.1e (including)
Ios_xeCisco3.8.1s (including)3.8.1s (including)
Ios_xeCisco3.8.2e (including)3.8.2e (including)
Ios_xeCisco3.8.2s (including)3.8.2s (including)
Ios_xeCisco3.8.3e (including)3.8.3e (including)
Ios_xeCisco3.8.4e (including)3.8.4e (including)
Ios_xeCisco3.8.5ae (including)3.8.5ae (including)
Ios_xeCisco3.8.5e (including)3.8.5e (including)
Ios_xeCisco3.8.6e (including)3.8.6e (including)
Ios_xeCisco3.8.7e (including)3.8.7e (including)
Ios_xeCisco3.8.8e (including)3.8.8e (including)
Ios_xeCisco3.8.9e (including)3.8.9e (including)
Ios_xeCisco3.8.10e (including)3.8.10e (including)
Ios_xeCisco3.8.10ee (including)3.8.10ee (including)
Ios_xeCisco3.9.0as (including)3.9.0as (including)
Ios_xeCisco3.9.0e (including)3.9.0e (including)
Ios_xeCisco3.9.0s (including)3.9.0s (including)
Ios_xeCisco3.9.1as (including)3.9.1as (including)
Ios_xeCisco3.9.1e (including)3.9.1e (including)
Ios_xeCisco3.9.1s (including)3.9.1s (including)
Ios_xeCisco3.9.2e (including)3.9.2e (including)
Ios_xeCisco3.9.2s (including)3.9.2s (including)
Ios_xeCisco3.10.0ce (including)3.10.0ce (including)
Ios_xeCisco3.10.0e (including)3.10.0e (including)
Ios_xeCisco3.10.0s (including)3.10.0s (including)
Ios_xeCisco3.10.1e (including)3.10.1e (including)
Ios_xeCisco3.10.1s (including)3.10.1s (including)
Ios_xeCisco3.10.1xbs (including)3.10.1xbs (including)
Ios_xeCisco3.10.2e (including)3.10.2e (including)
Ios_xeCisco3.10.2s (including)3.10.2s (including)
Ios_xeCisco3.10.2ts (including)3.10.2ts (including)
Ios_xeCisco3.10.3e (including)3.10.3e (including)
Ios_xeCisco3.10.3s (including)3.10.3s (including)
Ios_xeCisco3.10.4s (including)3.10.4s (including)
Ios_xeCisco3.10.5s (including)3.10.5s (including)
Ios_xeCisco3.10.6s (including)3.10.6s (including)
Ios_xeCisco3.10.7s (including)3.10.7s (including)
Ios_xeCisco3.10.8as (including)3.10.8as (including)
Ios_xeCisco3.10.8s (including)3.10.8s (including)
Ios_xeCisco3.10.9s (including)3.10.9s (including)
Ios_xeCisco3.10.10s (including)3.10.10s (including)
Ios_xeCisco3.11.0e (including)3.11.0e (including)
Ios_xeCisco3.11.0s (including)3.11.0s (including)
Ios_xeCisco3.11.1ae (including)3.11.1ae (including)
Ios_xeCisco3.11.1e (including)3.11.1e (including)
Ios_xeCisco3.11.1s (including)3.11.1s (including)
Ios_xeCisco3.11.2e (including)3.11.2e (including)
Ios_xeCisco3.11.2s (including)3.11.2s (including)
Ios_xeCisco3.11.3ae (including)3.11.3ae (including)
Ios_xeCisco3.11.3e (including)3.11.3e (including)
Ios_xeCisco3.11.3s (including)3.11.3s (including)
Ios_xeCisco3.11.4e (including)3.11.4e (including)
Ios_xeCisco3.11.4s (including)3.11.4s (including)
Ios_xeCisco3.11.5e (including)3.11.5e (including)
Ios_xeCisco3.11.6e (including)3.11.6e (including)
Ios_xeCisco3.11.7e (including)3.11.7e (including)
Ios_xeCisco3.11.8e (including)3.11.8e (including)
Ios_xeCisco3.11.9e (including)3.11.9e (including)
Ios_xeCisco3.11.10e (including)3.11.10e (including)
Ios_xeCisco3.12.0as (including)3.12.0as (including)
Ios_xeCisco3.12.0s (including)3.12.0s (including)
Ios_xeCisco3.12.1s (including)3.12.1s (including)
Ios_xeCisco3.12.2s (including)3.12.2s (including)
Ios_xeCisco3.12.3s (including)3.12.3s (including)
Ios_xeCisco3.12.4s (including)3.12.4s (including)
Ios_xeCisco3.13.0as (including)3.13.0as (including)
Ios_xeCisco3.13.0s (including)3.13.0s (including)
Ios_xeCisco3.13.1s (including)3.13.1s (including)
Ios_xeCisco3.13.2as (including)3.13.2as (including)
Ios_xeCisco3.13.2s (including)3.13.2s (including)
Ios_xeCisco3.13.3s (including)3.13.3s (including)
Ios_xeCisco3.13.4s (including)3.13.4s (including)
Ios_xeCisco3.13.5as (including)3.13.5as (including)
Ios_xeCisco3.13.5s (including)3.13.5s (including)
Ios_xeCisco3.13.6as (including)3.13.6as (including)
Ios_xeCisco3.13.6s (including)3.13.6s (including)
Ios_xeCisco3.13.7as (including)3.13.7as (including)
Ios_xeCisco3.13.7s (including)3.13.7s (including)
Ios_xeCisco3.13.8s (including)3.13.8s (including)
Ios_xeCisco3.13.9s (including)3.13.9s (including)
Ios_xeCisco3.13.10s (including)3.13.10s (including)
Ios_xeCisco3.14.0s (including)3.14.0s (including)
Ios_xeCisco3.14.1s (including)3.14.1s (including)
Ios_xeCisco3.14.2s (including)3.14.2s (including)
Ios_xeCisco3.14.3s (including)3.14.3s (including)
Ios_xeCisco3.14.4s (including)3.14.4s (including)
Ios_xeCisco3.15.0s (including)3.15.0s (including)
Ios_xeCisco3.15.1cs (including)3.15.1cs (including)
Ios_xeCisco3.15.1s (including)3.15.1s (including)
Ios_xeCisco3.15.2s (including)3.15.2s (including)
Ios_xeCisco3.15.3s (including)3.15.3s (including)
Ios_xeCisco3.15.4s (including)3.15.4s (including)
Ios_xeCisco3.16.0cs (including)3.16.0cs (including)
Ios_xeCisco3.16.0s (including)3.16.0s (including)
Ios_xeCisco3.16.1as (including)3.16.1as (including)
Ios_xeCisco3.16.1s (including)3.16.1s (including)
Ios_xeCisco3.16.2as (including)3.16.2as (including)
Ios_xeCisco3.16.2bs (including)3.16.2bs (including)
Ios_xeCisco3.16.2s (including)3.16.2s (including)
Ios_xeCisco3.16.3as (including)3.16.3as (including)
Ios_xeCisco3.16.3s (including)3.16.3s (including)
Ios_xeCisco3.16.4as (including)3.16.4as (including)
Ios_xeCisco3.16.4bs (including)3.16.4bs (including)
Ios_xeCisco3.16.4ds (including)3.16.4ds (including)
Ios_xeCisco3.16.4s (including)3.16.4s (including)
Ios_xeCisco3.16.5s (including)3.16.5s (including)
Ios_xeCisco3.16.6bs (including)3.16.6bs (including)
Ios_xeCisco3.16.6s (including)3.16.6s (including)
Ios_xeCisco3.16.7as (including)3.16.7as (including)
Ios_xeCisco3.16.7bs (including)3.16.7bs (including)
Ios_xeCisco3.16.7s (including)3.16.7s (including)
Ios_xeCisco3.16.8s (including)3.16.8s (including)
Ios_xeCisco3.16.9s (including)3.16.9s (including)
Ios_xeCisco3.16.10s (including)3.16.10s (including)
Ios_xeCisco3.17.0s (including)3.17.0s (including)
Ios_xeCisco3.17.1as (including)3.17.1as (including)
Ios_xeCisco3.17.1s (including)3.17.1s (including)
Ios_xeCisco3.17.2s (including)3.17.2s (including)
Ios_xeCisco3.17.3s (including)3.17.3s (including)
Ios_xeCisco3.17.4s (including)3.17.4s (including)
Ios_xeCisco3.18.0as (including)3.18.0as (including)
Ios_xeCisco3.18.0s (including)3.18.0s (including)
Ios_xeCisco3.18.0sp (including)3.18.0sp (including)
Ios_xeCisco3.18.1asp (including)3.18.1asp (including)
Ios_xeCisco3.18.1bsp (including)3.18.1bsp (including)
Ios_xeCisco3.18.1csp (including)3.18.1csp (including)
Ios_xeCisco3.18.1s (including)3.18.1s (including)
Ios_xeCisco3.18.1sp (including)3.18.1sp (including)
Ios_xeCisco3.18.2asp (including)3.18.2asp (including)
Ios_xeCisco3.18.2s (including)3.18.2s (including)
Ios_xeCisco3.18.2sp (including)3.18.2sp (including)
Ios_xeCisco3.18.3asp (including)3.18.3asp (including)
Ios_xeCisco3.18.3bsp (including)3.18.3bsp (including)
Ios_xeCisco3.18.3s (including)3.18.3s (including)
Ios_xeCisco3.18.3sp (including)3.18.3sp (including)
Ios_xeCisco3.18.4s (including)3.18.4s (including)
Ios_xeCisco3.18.4sp (including)3.18.4sp (including)
Ios_xeCisco3.18.5sp (including)3.18.5sp (including)
Ios_xeCisco3.18.6sp (including)3.18.6sp (including)
Ios_xeCisco3.18.7sp (including)3.18.7sp (including)
Ios_xeCisco3.18.8asp (including)3.18.8asp (including)
Ios_xeCisco3.18.9sp (including)3.18.9sp (including)
Ios_xeCisco16.1.1 (including)16.1.1 (including)
Ios_xeCisco16.1.2 (including)16.1.2 (including)
Ios_xeCisco16.1.3 (including)16.1.3 (including)
Ios_xeCisco16.2.1 (including)16.2.1 (including)
Ios_xeCisco16.2.2 (including)16.2.2 (including)
Ios_xeCisco16.3.1 (including)16.3.1 (including)
Ios_xeCisco16.3.1a (including)16.3.1a (including)
Ios_xeCisco16.3.2 (including)16.3.2 (including)
Ios_xeCisco16.3.3 (including)16.3.3 (including)
Ios_xeCisco16.3.4 (including)16.3.4 (including)
Ios_xeCisco16.3.5 (including)16.3.5 (including)
Ios_xeCisco16.3.5b (including)16.3.5b (including)
Ios_xeCisco16.3.6 (including)16.3.6 (including)
Ios_xeCisco16.3.7 (including)16.3.7 (including)
Ios_xeCisco16.3.8 (including)16.3.8 (including)
Ios_xeCisco16.3.9 (including)16.3.9 (including)
Ios_xeCisco16.3.10 (including)16.3.10 (including)
Ios_xeCisco16.3.11 (including)16.3.11 (including)
Ios_xeCisco16.4.1 (including)16.4.1 (including)
Ios_xeCisco16.4.2 (including)16.4.2 (including)
Ios_xeCisco16.4.3 (including)16.4.3 (including)
Ios_xeCisco16.5.1 (including)16.5.1 (including)
Ios_xeCisco16.5.1a (including)16.5.1a (including)
Ios_xeCisco16.5.1b (including)16.5.1b (including)
Ios_xeCisco16.5.2 (including)16.5.2 (including)
Ios_xeCisco16.5.3 (including)16.5.3 (including)
Ios_xeCisco16.6.1 (including)16.6.1 (including)
Ios_xeCisco16.6.2 (including)16.6.2 (including)
Ios_xeCisco16.6.3 (including)16.6.3 (including)
Ios_xeCisco16.6.4 (including)16.6.4 (including)
Ios_xeCisco16.6.4a (including)16.6.4a (including)
Ios_xeCisco16.6.5 (including)16.6.5 (including)
Ios_xeCisco16.6.5a (including)16.6.5a (including)
Ios_xeCisco16.6.6 (including)16.6.6 (including)
Ios_xeCisco16.6.7 (including)16.6.7 (including)
Ios_xeCisco16.6.8 (including)16.6.8 (including)
Ios_xeCisco16.6.9 (including)16.6.9 (including)
Ios_xeCisco16.6.10 (including)16.6.10 (including)
Ios_xeCisco16.7.1 (including)16.7.1 (including)
Ios_xeCisco16.7.1a (including)16.7.1a (including)
Ios_xeCisco16.7.1b (including)16.7.1b (including)
Ios_xeCisco16.7.2 (including)16.7.2 (including)
Ios_xeCisco16.7.3 (including)16.7.3 (including)
Ios_xeCisco16.7.4 (including)16.7.4 (including)
Ios_xeCisco16.8.1 (including)16.8.1 (including)
Ios_xeCisco16.8.1a (including)16.8.1a (including)
Ios_xeCisco16.8.1b (including)16.8.1b (including)
Ios_xeCisco16.8.1c (including)16.8.1c (including)
Ios_xeCisco16.8.1d (including)16.8.1d (including)
Ios_xeCisco16.8.1e (including)16.8.1e (including)
Ios_xeCisco16.8.1s (including)16.8.1s (including)
Ios_xeCisco16.8.2 (including)16.8.2 (including)
Ios_xeCisco16.8.3 (including)16.8.3 (including)
Ios_xeCisco16.9.1 (including)16.9.1 (including)
Ios_xeCisco16.9.1a (including)16.9.1a (including)
Ios_xeCisco16.9.1b (including)16.9.1b (including)
Ios_xeCisco16.9.1s (including)16.9.1s (including)
Ios_xeCisco16.9.2 (including)16.9.2 (including)
Ios_xeCisco16.9.3 (including)16.9.3 (including)
Ios_xeCisco16.9.3a (including)16.9.3a (including)
Ios_xeCisco16.9.4 (including)16.9.4 (including)
Ios_xeCisco16.9.5 (including)16.9.5 (including)
Ios_xeCisco16.9.5f (including)16.9.5f (including)
Ios_xeCisco16.9.6 (including)16.9.6 (including)
Ios_xeCisco16.9.7 (including)16.9.7 (including)
Ios_xeCisco16.9.8 (including)16.9.8 (including)
Ios_xeCisco16.10.1 (including)16.10.1 (including)
Ios_xeCisco16.10.1a (including)16.10.1a (including)
Ios_xeCisco16.10.1b (including)16.10.1b (including)
Ios_xeCisco16.10.1c (including)16.10.1c (including)
Ios_xeCisco16.10.1d (including)16.10.1d (including)
Ios_xeCisco16.10.1e (including)16.10.1e (including)
Ios_xeCisco16.10.1f (including)16.10.1f (including)
Ios_xeCisco16.10.1g (including)16.10.1g (including)
Ios_xeCisco16.10.1s (including)16.10.1s (including)
Ios_xeCisco16.10.2 (including)16.10.2 (including)
Ios_xeCisco16.10.3 (including)16.10.3 (including)
Ios_xeCisco16.11.1 (including)16.11.1 (including)
Ios_xeCisco16.11.1a (including)16.11.1a (including)
Ios_xeCisco16.11.1b (including)16.11.1b (including)
Ios_xeCisco16.11.1s (including)16.11.1s (including)
Ios_xeCisco16.11.2 (including)16.11.2 (including)
Ios_xeCisco16.12.1 (including)16.12.1 (including)
Ios_xeCisco16.12.1a (including)16.12.1a (including)
Ios_xeCisco16.12.1c (including)16.12.1c (including)
Ios_xeCisco16.12.1s (including)16.12.1s (including)
Ios_xeCisco16.12.1t (including)16.12.1t (including)
Ios_xeCisco16.12.1w (including)16.12.1w (including)
Ios_xeCisco16.12.1x (including)16.12.1x (including)
Ios_xeCisco16.12.1y (including)16.12.1y (including)
Ios_xeCisco16.12.1z1 (including)16.12.1z1 (including)
Ios_xeCisco16.12.1z2 (including)16.12.1z2 (including)
Ios_xeCisco16.12.2 (including)16.12.2 (including)
Ios_xeCisco16.12.2a (including)16.12.2a (including)
Ios_xeCisco16.12.2s (including)16.12.2s (including)
Ios_xeCisco16.12.3 (including)16.12.3 (including)
Ios_xeCisco16.12.3a (including)16.12.3a (including)
Ios_xeCisco16.12.3s (including)16.12.3s (including)
Ios_xeCisco16.12.4 (including)16.12.4 (including)
Ios_xeCisco16.12.4a (including)16.12.4a (including)
Ios_xeCisco16.12.5 (including)16.12.5 (including)
Ios_xeCisco16.12.5a (including)16.12.5a (including)
Ios_xeCisco16.12.5b (including)16.12.5b (including)
Ios_xeCisco16.12.6 (including)16.12.6 (including)
Ios_xeCisco16.12.6a (including)16.12.6a (including)
Ios_xeCisco16.12.7 (including)16.12.7 (including)
Ios_xeCisco16.12.8 (including)16.12.8 (including)
Ios_xeCisco16.12.9 (including)16.12.9 (including)
Ios_xeCisco16.12.10 (including)16.12.10 (including)
Ios_xeCisco16.12.10a (including)16.12.10a (including)
Ios_xeCisco16.12.11 (including)16.12.11 (including)
Ios_xeCisco17.1.1 (including)17.1.1 (including)
Ios_xeCisco17.1.1a (including)17.1.1a (including)
Ios_xeCisco17.1.1s (including)17.1.1s (including)
Ios_xeCisco17.1.1t (including)17.1.1t (including)
Ios_xeCisco17.1.3 (including)17.1.3 (including)
Ios_xeCisco17.2.1 (including)17.2.1 (including)
Ios_xeCisco17.2.1a (including)17.2.1a (including)
Ios_xeCisco17.2.1r (including)17.2.1r (including)
Ios_xeCisco17.2.1v (including)17.2.1v (including)
Ios_xeCisco17.2.2 (including)17.2.2 (including)
Ios_xeCisco17.2.3 (including)17.2.3 (including)
Ios_xeCisco17.3.1 (including)17.3.1 (including)
Ios_xeCisco17.3.1a (including)17.3.1a (including)
Ios_xeCisco17.3.1w (including)17.3.1w (including)
Ios_xeCisco17.3.1x (including)17.3.1x (including)
Ios_xeCisco17.3.1z (including)17.3.1z (including)
Ios_xeCisco17.3.2 (including)17.3.2 (including)
Ios_xeCisco17.3.2a (including)17.3.2a (including)
Ios_xeCisco17.3.3 (including)17.3.3 (including)
Ios_xeCisco17.3.4 (including)17.3.4 (including)
Ios_xeCisco17.3.4a (including)17.3.4a (including)
Ios_xeCisco17.3.4b (including)17.3.4b (including)
Ios_xeCisco17.3.4c (including)17.3.4c (including)
Ios_xeCisco17.3.5 (including)17.3.5 (including)
Ios_xeCisco17.3.5a (including)17.3.5a (including)
Ios_xeCisco17.3.5b (including)17.3.5b (including)
Ios_xeCisco17.3.6 (including)17.3.6 (including)
Ios_xeCisco17.3.7 (including)17.3.7 (including)
Ios_xeCisco17.3.8 (including)17.3.8 (including)
Ios_xeCisco17.3.8a (including)17.3.8a (including)
Ios_xeCisco17.4.1 (including)17.4.1 (including)
Ios_xeCisco17.4.1a (including)17.4.1a (including)
Ios_xeCisco17.4.1b (including)17.4.1b (including)
Ios_xeCisco17.4.2 (including)17.4.2 (including)
Ios_xeCisco17.4.2a (including)17.4.2a (including)
Ios_xeCisco17.5.1 (including)17.5.1 (including)
Ios_xeCisco17.5.1a (including)17.5.1a (including)
Ios_xeCisco17.6.1 (including)17.6.1 (including)
Ios_xeCisco17.6.1a (including)17.6.1a (including)
Ios_xeCisco17.6.1w (including)17.6.1w (including)
Ios_xeCisco17.6.1x (including)17.6.1x (including)
Ios_xeCisco17.6.1y (including)17.6.1y (including)
Ios_xeCisco17.6.1z (including)17.6.1z (including)
Ios_xeCisco17.6.1z1 (including)17.6.1z1 (including)
Ios_xeCisco17.6.2 (including)17.6.2 (including)
Ios_xeCisco17.6.3 (including)17.6.3 (including)
Ios_xeCisco17.6.3a (including)17.6.3a (including)
Ios_xeCisco17.6.4 (including)17.6.4 (including)
Ios_xeCisco17.6.5 (including)17.6.5 (including)
Ios_xeCisco17.6.5a (including)17.6.5a (including)
Ios_xeCisco17.6.6 (including)17.6.6 (including)
Ios_xeCisco17.6.6a (including)17.6.6a (including)
Ios_xeCisco17.6.7 (including)17.6.7 (including)
Ios_xeCisco17.7.1 (including)17.7.1 (including)
Ios_xeCisco17.7.1a (including)17.7.1a (including)
Ios_xeCisco17.7.1b (including)17.7.1b (including)
Ios_xeCisco17.7.2 (including)17.7.2 (including)
Ios_xeCisco17.8.1 (including)17.8.1 (including)
Ios_xeCisco17.8.1a (including)17.8.1a (including)
Ios_xeCisco17.9.1 (including)17.9.1 (including)
Ios_xeCisco17.9.1a (including)17.9.1a (including)
Ios_xeCisco17.9.1w (including)17.9.1w (including)
Ios_xeCisco17.9.1x (including)17.9.1x (including)
Ios_xeCisco17.9.1x1 (including)17.9.1x1 (including)
Ios_xeCisco17.9.1y (including)17.9.1y (including)
Ios_xeCisco17.9.1y1 (including)17.9.1y1 (including)
Ios_xeCisco17.9.2 (including)17.9.2 (including)
Ios_xeCisco17.9.2a (including)17.9.2a (including)
Ios_xeCisco17.9.3 (including)17.9.3 (including)
Ios_xeCisco17.9.3a (including)17.9.3a (including)
Ios_xeCisco17.9.4 (including)17.9.4 (including)
Ios_xeCisco17.9.4a (including)17.9.4a (including)
Ios_xeCisco17.9.5 (including)17.9.5 (including)
Ios_xeCisco17.9.5a (including)17.9.5a (including)
Ios_xeCisco17.9.5b (including)17.9.5b (including)
Ios_xeCisco17.10.1 (including)17.10.1 (including)
Ios_xeCisco17.10.1a (including)17.10.1a (including)
Ios_xeCisco17.10.1b (including)17.10.1b (including)
Ios_xeCisco17.11.1 (including)17.11.1 (including)
Ios_xeCisco17.11.1a (including)17.11.1a (including)
Ios_xeCisco17.11.99sw (including)17.11.99sw (including)
Ios_xeCisco17.12.1 (including)17.12.1 (including)
Ios_xeCisco17.12.1a (including)17.12.1a (including)
Ios_xeCisco17.12.1w (including)17.12.1w (including)
Ios_xeCisco17.12.1x (including)17.12.1x (including)
Ios_xeCisco17.12.1y (including)17.12.1y (including)
Ios_xeCisco17.12.2 (including)17.12.2 (including)
Ios_xeCisco17.12.2a (including)17.12.2a (including)
Ios_xeCisco17.12.3 (including)17.12.3 (including)
Ios_xeCisco17.12.3a (including)17.12.3a (including)
Ios_xeCisco17.13.1 (including)17.13.1 (including)
Ios_xeCisco17.13.1a (including)17.13.1a (including)

Potential Mitigations

  • Divide the product into anonymous, normal, privileged, and administrative areas. Reduce the attack surface by carefully mapping roles with data and functionality. Use role-based access control (RBAC) to enforce the roles at the appropriate boundaries.
  • Note that this approach may not protect against horizontal authorization, i.e., it will not protect a user from attacking others with the same role.
  • Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid.
  • For example, consider using authorization frameworks such as the JAAS Authorization Framework [REF-233] and the OWASP ESAPI Access Control feature [REF-45].
  • For web applications, make sure that the access control mechanism is enforced correctly at the server side on every page. Users should not be able to access any unauthorized functionality or information by simply requesting direct access to that page.
  • One way to do this is to ensure that all pages containing sensitive information are not cached, and that all such pages restrict access to requests that are accompanied by an active and authenticated session token associated with a user who has the required permissions to access that page.

References