CVE-2024-20435

A vulnerability in the CLI of Cisco AsyncOS for Secure Web Appliance could allow an authenticated, local attacker to execute arbitrary commands and elevate privileges to root. This vulnerability is

Severity
High 8.8
CVSS 3.1
Adjacent, local or physical access what this means
Exploited
Not listed
EPSS
0.002
5.1th percentile
Discovered by
Third party
Vendor-published field
Published
Jul 17, 2024
Assigned by cisco

Description

A vulnerability in the CLI of Cisco AsyncOS for Secure Web Appliance could allow an authenticated, local attacker to execute arbitrary commands and elevate privileges to root. This vulnerability is due to insufficient validation of user-supplied input for the CLI. An attacker could exploit this vulnerability by authenticating to the system and executing a crafted command on the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system and elevate privileges to root. To successfully exploit this vulnerability, an attacker would need at least guest credentials.

Weakness: CWE-250

Affected products

Vendor Product Category Matched by
Cisco Cisco Secure Web Appliance SASE / SSE / Secure Web cna-assigner
Vendor-reported products (2)
  • Cisco · Cisco Secure Web Appliance
  • cisco · secure_web_appliance

Vendor advisory

cisco-sa-swa-priv-esc-7uHpZsCC

Cisco Secure Web Appliance Privilege Escalation Vulnerability

Cisco’s rating: High (advisory CVSS 8.8) · Published Jul 17, 2024 · updated Nov 22, 2024 (revision 1.1)

Bug ID: CSCwj30015

The vendor’s rating applies to the whole advisory and can differ from this CVE’s own CVSS severity. Where this comes from

Something wrong here?