Time-of-check Time-of-use (TOCTOU) Race Condition in Cisco IOS XR Software



Published: 2023-09-14
Risk Low
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2023-20135
CWE-ID CWE-367
Exploitation vector Local
Public exploit N/A
Vulnerable software
Subscribe
Cisco IOS XR
Operating systems & Components / Operating system

Cisco 8000 Series Routers
Hardware solutions / Routers & switches, VoIP, GSM, etc

Cisco Network Convergence System 540 Series Routers
Hardware solutions / Routers & switches, VoIP, GSM, etc

Network Convergence System 5700 Series
Other software / Other software solutions

Vendor Cisco Systems, Inc

Security Bulletin

This security bulletin contains one low risk vulnerability.

1) Time-of-check Time-of-use (TOCTOU) Race Condition

EUVDB-ID: #VU80775

Risk: Low

CVSSv3.1: 5.6 [CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2023-20135

CWE-ID: CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition

Exploit availability: No

Description

The vulnerability allows a local user to execute arbitrary code on the system.

The vulnerability exists due to a time-of-check, time-of-use (TOCTOU) race condition when an install query regarding an ISO image is performed during an install operation that uses an ISO image. A local administrator can execute arbitrary code on target system.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Cisco IOS XR: 7.5.2 - 7.7.0

Cisco 8000 Series Routers: All versions

Cisco Network Convergence System 540 Series Routers: All versions

Network Convergence System 5700 Series: All versions

External links

http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-lnt-L9zOkBz5


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###