CVE Feed

    Dashboard / CVE / CVE-2024-20381

    CVE-2024-20381

    A vulnerability in the JSON-RPC API feature in Cisco Crosswork Network Services Orchestrator (NSO) and ConfD that is used by the web-based management interfaces of Cisco Optical Site Manager and Cisco RV340 Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to modify the configuration of an affected application or device.  This vulnerability is due to improper authorization checks on the API. An attacker with privileges sufficient to access the affected application or device could exploit this vulnerability by sending malicious requests to the JSON-RPC API. A successful exploit could allow the attacker to make unauthorized modifications to the configuration of the affected application or device, including creating new user accounts or elevating their own privileges on an affected system.

    Published:Sep 11, 2024
    Last Modified:Oct 8, 2024
    EPS:Sep 11, 2024
    EPSS Score:0.00236
    CVSS Score:8.8

    Affected Products

    Vendor
    Cisco
    Product
    Ios Xr
    Vendor
    Cisco
    Product
    Network Services Orchestrator
    Vendor
    Cisco
    Product
    Small Business Rv Series Router Firmware

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High