CVE-2024-20456
MEDIUMDescription
A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local attacker with high privileges to bypass the Cisco Secure Boot functionality and load unverified software on an affected device. To exploit this successfully, the attacker must have root-system privileges on the affected device. This vulnerability is due to an error in the software build process. An attacker could exploit this vulnerability by manipulating the system’s configuration options to bypass some of the integrity checks that are performed during the booting process. A successful exploit could allow the attacker to control the boot configuration, which could enable them to bypass of the requirement to run Cisco signed images or alter the security properties of the running system.
Is your site exposed to CVE-2024-20456?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| cisco | ios_xr |
| cisco | 8011-4g24y4h-i |
| cisco | 8101-32fh |
| cisco | 8101-32fh-o |
| cisco | 8101-32h-o |
| cisco | 8102-28fh-dpu-o |
| cisco | 8102-64h |
| cisco | 8102-64h-o |
| cisco | 8111-32eh-o |
| cisco | 8122-64eh-o |
| cisco | 8122-64ehf-o |
| cisco | 8201 |
| cisco | 8201-24h8fh |
| cisco | 8201-32fh |
| cisco | 8201-32fh-o |
| cisco | 8202 |
| cisco | 8202-32fh-m |
| cisco | 8212-48fh-m |
| cisco | 8404 |
| cisco | 8501-sys-mt |
| cisco | 8608 |
| cisco | 8700 |
| cisco | 8711-32fh-m |
| cisco | 8712-mod-m |
| cisco | 8804 |
| cisco | 8808 |
| cisco | 8812 |
| cisco | 8818 |
| cisco | ncs_1010 |
| cisco | ncs_1014 |
| cisco | ncs_540-12z20g-sys-a |
| cisco | ncs_540-12z20g-sys-d |
| cisco | ncs_540-24q2c2dd-sys |
| cisco | ncs_540-24q8l2dd-sys |
| cisco | ncs_540-24z8q2c-sys |
| cisco | ncs_540-28z4c-sys-a |
| cisco | ncs_540-28z4c-sys-d |
| cisco | ncs_540-6z14s-sys-d |
| cisco | ncs_540-6z18g-sys-a |
| cisco | ncs_540-6z18g-sys-d |
| cisco | ncs_540-acc-sys |
| cisco | ncs_540-fh-agg |
| cisco | ncs_540-fh-csr-sys |
| cisco | ncs_540x-12z16g-sys-a |
| cisco | ncs_540x-12z16g-sys-d |
| cisco | ncs_540x-16z4g8q2c-a |
| cisco | ncs_540x-16z4g8q2c-d |
| cisco | ncs_540x-16z8q2c-d |
| cisco | ncs_540x-4z14g2q-a |
| cisco | ncs_540x-4z14g2q-d |
| cisco | ncs_540x-6z18g-sys-a |
| cisco | ncs_540x-6z18g-sys-d |
| cisco | ncs_540x-8z16g-sys-a |
| cisco | ncs_540x-8z16g-sys-d |
| cisco | ncs_540x-acc-sys |
| cisco | ncs_57b1-5dse-sys |
| cisco | ncs_57b1-6d24-sys |
| cisco | ncs_57c1-48q6-sys |
| cisco | ncs_57d2-18dd-sys |
References
Frequently Asked Questions
What is CVE-2024-20456? +
How severe is CVE-2024-20456? +
What products are affected by CVE-2024-20456? +
How do I check if I'm vulnerable to CVE-2024-20456? +
Related Vulnerabilities
An improper access control vulnerability in the canonical-livepatch snap client prior to version 10.15.0 allows a local unprivileged user to …
NitroSense 3.x before 3.01.3052 contains Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom …
Incorrect Permission Assignment for Critical Resource vulnerability in ILM Informatique OpenConcerto allows Replace Binaries. This issue affects OpenConcerto: 1.7.5.
PredatorSense version 3.00.3136 to 3.00.3196 contain Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a …
An Incorrect Permission Assignment Vulnerability exists in the product and version listed above. The vulnerability is due to incorrect permissions …
DaVinci Resolve on MacOS was found to be installed with incorrect file permissions (rwxrwxrwx). This is inconsistent with standard macOS …