SB2024032809 - Trust Boundary Violation in Cisco Access Point Software
Published: March 28, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Trust Boundary Violation (CVE-ID: CVE-2024-20265)
CWE-ID: CWE-501 - Trust Boundary Violation
CVSSv4: CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a local attacker to compromise the target system.
The vulnerability exists due to unnecessary commands are available during boot time at the physical console. An authenticated attacker with physical access can bypass the Cisco Secure Boot functionality and load arbitrary software image on the target device.
Remediation
Install update from vendor's website.