Improper Authentication in Cisco Systems, Inc products - CVE-2024-20381

 

Improper Authentication in Cisco Systems, Inc products - CVE-2024-20381

Published: September 13, 2024


Vulnerability identifier: #VU97228
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-20381
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error when processing authentication requests in the JSON-RPC API feature. A remote user can make unauthorized modifications to the configuration of the affected application or device.


Affected software

Optical Site Manager
Cisco RV340 Dual WAN Gigabit VPN Router
Crosswork Network Services Orchestrator
ConfD

How to mitigate CVE-2024-20381

Install updates from vendor's website.

Optical Site Manager - update to 24.3.1
Crosswork Network Services Orchestrator - addressed in versions 5.5.10.1, 5.6.14.3, 5.7.16, 5.8.13.1, 6.0.13, 6.1.8.1, 6.1.9, 6.2.3
ConfD - addressed in versions 7.5.10.2, 7.7.16, 8.0.13

External References

Related Security Bulletins