Improper Authentication in Cisco Systems, Inc products - CVE-2024-20381
Published: September 13, 2024
Vulnerability identifier: #VU97228
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-20381
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error when processing authentication requests in the JSON-RPC API feature. A remote user can make unauthorized modifications to the configuration of the affected application or device.
Affected software
Optical Site Manager
Cisco RV340 Dual WAN Gigabit VPN Router
Crosswork Network Services Orchestrator
ConfD
Cisco RV340 Dual WAN Gigabit VPN Router
Crosswork Network Services Orchestrator
ConfD
How to mitigate CVE-2024-20381
Install updates from vendor's website.
Optical Site Manager - update to 24.3.1
Crosswork Network Services Orchestrator - addressed in versions 5.5.10.1, 5.6.14.3, 5.7.16, 5.8.13.1, 6.0.13, 6.1.8.1, 6.1.9, 6.2.3
ConfD - addressed in versions 7.5.10.2, 7.7.16, 8.0.13
Crosswork Network Services Orchestrator - addressed in versions 5.5.10.1, 5.6.14.3, 5.7.16, 5.8.13.1, 6.0.13, 6.1.8.1, 6.1.9, 6.2.3
ConfD - addressed in versions 7.5.10.2, 7.7.16, 8.0.13