Time-of-check Time-of-use (TOCTOU) Race Condition in Cisco Systems, Inc products - CVE-2023-20135
Published: September 14, 2023
Vulnerability details
The vulnerability allows a local user to execute arbitrary code on the system.
The vulnerability exists due to a time-of-check, time-of-use (TOCTOU) race condition when an install query regarding an ISO image is performed during an install operation that uses an ISO image. A local administrator can execute arbitrary code on target system.
Affected software
Cisco Network Convergence System 540 Series Routers
Network Convergence System 5700 Series
Cisco IOS XR