Back to overview

CVE-2024-20418

CRITICAL
10.0
CVSS 3.1
Description
A vulnerability in the web-based management interface of Cisco Unified Industrial Wireless Software for Cisco Ultra-Reliable Wireless Backhaul (URWB) Access Points could allow an unauthenticated, remote attacker to perform command injection attacks with root privileges on the underlying operating system. This vulnerability is due to improper validation of input to the web-based management interface. An attacker could exploit this vulnerability by sending crafted HTTP requests to the web-based management interface of an affected system. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the underlying operating system of the affected device.

Metadata

CVE ID
CVE-2024-20418
State
PUBLISHED
Assigner
cisco
Reserved
2023-11-08 15:08 UTC
Published
2024-11-06 16:59 UTC
Last updated
2024-11-08 04:55 UTC
Primary CWE
CWE-77
Improper Neutralization of Special Elements used in a Comman…
Vendor / Product
Cisco / Cisco Aironet Access Point Software (IOS XE Controller)
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Cisco Cisco Aironet Access Point Software (IOS XE Controller) N/A
Weakness (CWE)
CWESourceDescription
CWE-77 cna Improper Neutralization of Special Elements used in a Command ('Command Injection')
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview