CVE-2024-20381

HIGHCVSS 8.8/10EPSS 0.58%

Last modified

CVE-2024-20381 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A vulnerability in the JSON-RPC API feature in Cisco Crosswork Network Services Orchestrator (NSO) and ConfD that is used by the web-based management interfaces of Cisco Optical Site Manager and Cisco RV340 Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to modify the configuration of an affected application or device.  This vulnerability is due to improper authorization checks on the API. An attacker with privileges sufficient to access the affected application or device could exploit this vulnerability by sending malicious requests to the JSON-RPC API. EPSS estimates a 0.58% chance of exploitation in the next 30 days.

Description

A vulnerability in the JSON-RPC API feature in Cisco Crosswork Network Services Orchestrator (NSO) and ConfD that is used by the web-based management interfaces of Cisco Optical Site Manager and Cisco RV340 Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to modify the configuration of an affected application or device.  This vulnerability is due to improper authorization checks on the API. An attacker with privileges sufficient to access the affected application or device could exploit this vulnerability by sending malicious requests to the JSON-RPC API. A successful exploit could allow the attacker to make unauthorized modifications to the configuration of the affected application or device, including creating new user accounts or elevating their own privileges on an affected system.

Metrics

CVSS 3.1
8.8/10

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.58%

43.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
CiscoIos Xr6.5.1
CiscoIos Xr6.5.2
CiscoIos Xr6.5.3
CiscoIos Xr6.5.15
CiscoIos Xr6.5.25
CiscoIos Xr6.5.26
CiscoIos Xr6.5.28
CiscoIos Xr6.5.29
CiscoIos Xr6.5.31
CiscoIos Xr6.5.32
CiscoIos Xr6.5.33
CiscoIos Xr6.5.90
CiscoIos Xr6.5.92
CiscoIos Xr6.5.93
CiscoIos Xr6.6.1
CiscoIos Xr6.6.2
CiscoIos Xr6.6.3
CiscoIos Xr6.6.4
CiscoIos Xr6.6.11
CiscoIos Xr6.6.12
CiscoIos Xr6.6.25
CiscoIos Xr6.7.1
CiscoIos Xr6.7.2
CiscoIos Xr6.7.3
CiscoIos Xr6.7.4
CiscoIos Xr6.7.35
CiscoIos Xr6.8.1
CiscoIos Xr6.8.2
CiscoIos Xr6.9.1
CiscoIos Xr6.9.2
CiscoIos Xr7.0.0
CiscoIos Xr7.0.1
CiscoIos Xr7.0.2
CiscoIos Xr7.0.11
CiscoIos Xr7.0.12
CiscoIos Xr7.0.14
CiscoIos Xr7.0.90
CiscoIos Xr7.1.1
CiscoIos Xr7.1.2
CiscoIos Xr7.1.3
CiscoIos Xr7.1.15
CiscoIos Xr7.1.25
CiscoIos Xr7.2.0
CiscoIos Xr7.2.1
CiscoIos Xr7.2.2
CiscoIos Xr7.2.12
CiscoIos Xr7.3.1
CiscoIos Xr7.3.2
CiscoIos Xr7.3.3
CiscoIos Xr7.3.4

Showing 50 of 271 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2024-20381?
A vulnerability in the JSON-RPC API feature in Cisco Crosswork Network Services Orchestrator (NSO) and ConfD that is used by the web-based management interfaces of Cisco Optical Site Manager and Cisco RV340 Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to modify the configuration of an affected application or device.  This vulnerability is due to improper authorization checks on the API. An attacker with privileges sufficient to access the affected application or device could exploit this vulnerability by sending malicious requests to the JSON-RPC API. A successful exploit could allow the attacker to make unauthorized modifications to the configuration of the affected application or device, including creating new user accounts or elevating their own privileges on an affected system.
How severe is CVE-2024-20381?
CVE-2024-20381 has a CVSS score of 8.8/10 (HIGH severity). The EPSS model estimates a 0.58% probability of exploitation in the next 30 days.
How do I fix CVE-2024-20381?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2024-20381?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST