CVE-2024-20286
Cisco NX-OS Software Python Parser Escape Vulnerability
Description
A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to escape the Python sandbox and gain unauthorized access to the underlying operating system of the device. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by manipulating specific functions within the Python interpreter. A successful exploit could allow an attacker to escape the Python sandbox and execute arbitrary commands on the underlying operating system with the privileges of the authenticated user. Note: An attacker must be authenticated with Python execution privileges to exploit these vulnerabilities. For more information regarding Python execution privileges, see product-specific documentation, such as the section of the Cisco Nexus 9000 Series NX-OS Programmability Guide.
Weakness: CWE-693
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | Cisco NX-OS Software | Routing & Switching | cna-assigner |
Vendor-reported products (1)
- Cisco · Cisco NX-OS Software
Vendor advisory
cisco-sa-nxos-psbe-ce-YvbTn5du
Cisco NX-OS Software Python Sandbox Escape Vulnerabilities
Cisco’s rating: Medium (advisory CVSS 5.3) · Published Aug 28, 2024
Bug IDs: CSCwh77779 , CSCwh77780 , CSCwh77781 , CSCwi52362 , CSCwi52363 , CSCwi52365 , CSCwi52380 , CSCwi52383 , CSCwi52460 , CSCwi52461
The vendor’s rating applies to the whole advisory and can differ from this CVE’s own CVSS severity. Where this comes from