7.8

CVE-2023-20236

A vulnerability in the iPXE boot function of Cisco IOS XR software could allow an authenticated, local attacker to install an unverified software image on an affected device.

 This vulnerability is due to insufficient image verification. An attacker could exploit this vulnerability by manipulating the boot parameters for image verification during the iPXE boot process on an affected device. A successful exploit could allow the attacker to boot an unverified software image on the affected device.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CiscoIos Xr Version < 7.10.1
   Cisco8201 Version-
   Cisco8202 Version-
   Cisco8208 Version-
   Cisco8212 Version-
   Cisco8218 Version-
   Cisco8804 Version-
   Cisco8808 Version-
   Cisco8812 Version-
   Cisco8818 Version-
   Cisco8831 Version-
   CiscoAsr 9000 Version-
   CiscoAsr 9000v Version-
   CiscoAsr 9001 Version-
   CiscoAsr 9006 Version-
   CiscoAsr 9010 Version-
   CiscoAsr 9901 Version-
   CiscoAsr 9902 Version-
   CiscoAsr 9903 Version-
   CiscoAsr 9904 Version-
   CiscoAsr 9906 Version-
   CiscoAsr 9910 Version-
   CiscoAsr 9912 Version-
   CiscoAsr 9920 Version-
   CiscoAsr 9922 Version-
   CiscoNcs 1001 Version-
   CiscoNcs 1002 Version-
   CiscoNcs 1004 Version-
   CiscoNcs 4009 Version-
   CiscoNcs 4016 Version-
   CiscoNcs 4201 Version-
   CiscoNcs 4202 Version-
   CiscoNcs 4206 Version-
   CiscoNcs 4216 Version-
   CiscoNcs 5001 Version-
   CiscoNcs 5002 Version-
   CiscoNcs 5011 Version-
   CiscoNcs 540 Version-
   CiscoNcs 5500 Version-
   CiscoNcs 5501 Version-
   CiscoNcs 5501 Versionse
   CiscoNcs 5502 Version-
   CiscoNcs 5502 Versionse
   CiscoNcs 5504 Version-
   CiscoNcs 5508 Version-
   CiscoNcs 5516 Version-
   CiscoNcs 560 Version-
   CiscoNcs 560-4 Version-
   CiscoNcs 560-7 Version-
   CiscoNcs 57b1-5dse-sys Version-
   CiscoNcs 57b1-6d24-sys Version-
   CiscoNcs 57c1-48q6-sys Version-
   CiscoNcs 57c3-mod-sys Version-
   CiscoNcs 57c3-mods-sys Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.02% 0.036
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
psirt@cisco.com 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-345 Insufficient Verification of Data Authenticity

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

CWE-347 Improper Verification of Cryptographic Signature

The product does not verify, or incorrectly verifies, the cryptographic signature for data.