CVE-2024-20320

HIGH
Published Mar 13, 2024 Modified Aug 5, 2025 CWE-266

Description

A vulnerability in the SSH client feature of Cisco IOS XR Software for Cisco 8000 Series Routers and Cisco Network Convergence System (NCS) 540 Series and 5700 Series Routers could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient validation of arguments that are included with the SSH client CLI command. An attacker with low-privileged access to an affected device could exploit this vulnerability by issuing a crafted SSH client command to the CLI. A successful exploit could allow the attacker to elevate privileges to root on the affected device.

Is your site exposed to CVE-2024-20320?

Run a free security scan — no signup, results in seconds.

CVSS v3.1 Score

7.8
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weakness Type (CWE)

CWE-266 CWE-266

Affected Products

Vendor Product
cisco ios_xr
cisco ios_xr
cisco ios_xr
cisco ios_xr
cisco ios_xr
cisco ios_xr
cisco ios_xr
cisco ios_xr
cisco ios_xr
cisco ios_xr
cisco ios_xr
cisco ios_xr
cisco ios_xr
cisco ios_xr
cisco ios_xr
cisco ios_xr
cisco ios_xr
cisco ios_xr
cisco ios_xr
cisco ios_xr
cisco ios_xr
cisco ios_xr
cisco ios_xr
cisco ios_xr
cisco ios_xr
cisco ios_xrd_control_plane
cisco ios_xrd_vrouter
cisco 8011-4g24y4h-i
cisco 8101-32fh
cisco 8101-32fh-o
cisco 8101-32h-o
cisco 8102-28fh-dpu-o
cisco 8102-64h
cisco 8102-64h-o
cisco 8111-32eh-o
cisco 8122-64eh-o
cisco 8122-64ehf-o
cisco 8201
cisco 8201-24h8fh
cisco 8201-32fh
cisco 8201-32fh-o
cisco 8202
cisco 8202-32fh-m
cisco 8212-48fh-m
cisco 8404
cisco 8501-sys-mt
cisco 8608
cisco 8700
cisco 8711-32fh-m
cisco 8712-mod-m
cisco 8804
cisco 8808
cisco 8812
cisco 8818
cisco ncs_540-12z20g-sys-a
cisco ncs_540-12z20g-sys-d
cisco ncs_540-24q2c2dd-sys
cisco ncs_540-24q8l2dd-sys
cisco ncs_540-24z8q2c-sys
cisco ncs_540-28z4c-sys-a
cisco ncs_540-28z4c-sys-d
cisco ncs_540-6z14s-sys-d
cisco ncs_540-6z18g-sys-a
cisco ncs_540-6z18g-sys-d
cisco ncs_540-acc-sys
cisco ncs_540-fh-agg
cisco ncs_540-fh-csr-sys
cisco ncs_540x-12z16g-sys-a
cisco ncs_540x-12z16g-sys-d
cisco ncs_540x-16z4g8q2c-a
cisco ncs_540x-16z4g8q2c-d
cisco ncs_540x-16z8q2c-d
cisco ncs_540x-4z14g2q-a
cisco ncs_540x-4z14g2q-d
cisco ncs_540x-6z18g-sys-a
cisco ncs_540x-6z18g-sys-d
cisco ncs_540x-8z16g-sys-a
cisco ncs_540x-8z16g-sys-d
cisco ncs_540x-acc-sys
cisco ncs_57b1-5dse-sys
cisco ncs_57b1-6d24-sys
cisco ncs_57c1-48q6-sys

References

Frequently Asked Questions

What is CVE-2024-20320? +
A vulnerability in the SSH client feature of Cisco IOS XR Software for Cisco 8000 Series Routers and Cisco Network Convergence System (NCS) 540 Series and 5700 Series Routers could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient validation of arguments that are included with the SSH client CLI command. An attacker with low-privileged access to an affected device could exploit this vulnerability by issuing a crafted SSH client command to the CLI. A successful exploit could allow the attacker to elevate privileges to root on the affected device. It has a CVSS v3.1 base score of 7.8 (HIGH).
How severe is CVE-2024-20320? +
CVE-2024-20320 has a CVSS v3.1 score of 7.8 out of 10, rated HIGH. This is a high-severity vulnerability that should be prioritized for patching.
What products are affected by CVE-2024-20320? +
CVE-2024-20320 affects products from cisco, specifically: 8011-4g24y4h-i, 8101-32fh, 8101-32fh-o, 8101-32h-o, 8102-28fh-dpu-o, 8102-64h, 8102-64h-o, 8111-32eh-o, 8122-64eh-o, 8122-64ehf-o, 8201, 8201-24h8fh, 8201-32fh, 8201-32fh-o, 8202, 8202-32fh-m, 8212-48fh-m, 8404, 8501-sys-mt, 8608, 8700, 8711-32fh-m, 8712-mod-m, 8804, 8808, 8812, 8818, ios_xr, ios_xrd_control_plane, ios_xrd_vrouter, ncs_540-12z20g-sys-a, ncs_540-12z20g-sys-d, ncs_540-24q2c2dd-sys, ncs_540-24q8l2dd-sys, ncs_540-24z8q2c-sys, ncs_540-28z4c-sys-a, ncs_540-28z4c-sys-d, ncs_540-6z14s-sys-d, ncs_540-6z18g-sys-a, ncs_540-6z18g-sys-d, ncs_540-acc-sys, ncs_540-fh-agg, ncs_540-fh-csr-sys, ncs_540x-12z16g-sys-a, ncs_540x-12z16g-sys-d, ncs_540x-16z4g8q2c-a, ncs_540x-16z4g8q2c-d, ncs_540x-16z8q2c-d, ncs_540x-4z14g2q-a, ncs_540x-4z14g2q-d, ncs_540x-6z18g-sys-a, ncs_540x-6z18g-sys-d, ncs_540x-8z16g-sys-a, ncs_540x-8z16g-sys-d, ncs_540x-acc-sys, ncs_57b1-5dse-sys, ncs_57b1-6d24-sys, ncs_57c1-48q6-sys. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2024-20320? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2024-20320 — free, no signup required.