CVE-2024-20435

A vulnerability in the CLI of Cisco AsyncOS for Secure Web Appliance could allow an authenticated, local attacker to execute arbitrary commands and elevate privileges to root. This vulnerability is

Severity
High 8.8
CVSS 3.1
Exploited
Not listed
EPSS
0.002
6.0th percentile
Discovered by
Third party
Published by the vendor
Published
Jul 17, 2024
Assigned by cisco

Description

A vulnerability in the CLI of Cisco AsyncOS for Secure Web Appliance could allow an authenticated, local attacker to execute arbitrary commands and elevate privileges to root. This vulnerability is due to insufficient validation of user-supplied input for the CLI. An attacker could exploit this vulnerability by authenticating to the system and executing a crafted command on the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system and elevate privileges to root. To successfully exploit this vulnerability, an attacker would need at least guest credentials.

Weakness: CWE-250

Affected products

Vendor Product Category Matched by
Cisco Cisco Secure Web Appliance SASE / SSE / Secure Web cna-assigner
Vendor-reported affected versions (2)
  • Cisco · Cisco Secure Web Appliance
  • cisco · secure_web_appliance