SB2024032809 - Trust Boundary Violation in Cisco Access Point Software
Published: March 28, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Trust Boundary Violation (CVE-ID: CVE-2024-20265)
The vulnerability allows a local attacker to compromise the target system.
The vulnerability exists due to unnecessary commands are available during boot time at the physical console. An authenticated attacker with physical access can bypass the Cisco Secure Boot functionality and load arbitrary software image on the target device.
Remediation
Install update from vendor's website.