Execution with unnecessary privileges in Cisco Application Policy Infrastructure Controller and Cisco Cloud Network Controller - CVE-2024-20478
Published: August 29, 2024
Vulnerability identifier: #VU96604
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-20478
CWE-ID: CWE-250
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to insufficient signature validation of software images. A remote administrator can execute arbitrary code and elevate their privileges to root.
Affected software
Cisco Application Policy Infrastructure Controller
Cisco Cloud Network Controller
Cisco Cloud Network Controller
How to mitigate CVE-2024-20478
Install updates from vendor's website.
Cisco Application Policy Infrastructure Controller - addressed in versions 5.3(2d), 6.0(6c)