CVE-2024-20381
Description
A vulnerability in the JSON-RPC API feature in Cisco Crosswork Network Services Orchestrator (NSO) and ConfD that is used by the web-based management interfaces of Cisco Optical Site Manager and Cisco RV340 Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to modify the configuration of an affected application or device. This vulnerability is due to improper authorization checks on the API. An attacker with privileges sufficient to access the affected application or device could exploit this vulnerability by sending malicious requests to the JSON-RPC API. A successful exploit could allow the attacker to make unauthorized modifications to the configuration of the affected application or device, including creating new user accounts or elevating their own privileges on an affected system.
CVSS Details
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Threat Intelligence
Weaknesses 1
Affected Products 271
| Vendor | Product | Version | Range |
|---|---|---|---|
| cisco | ios_xr | 6.5.1 | any |
| cisco | ios_xr | 6.5.2 | any |
| cisco | ios_xr | 6.5.3 | any |
| cisco | ios_xr | 6.5.15 | any |
| cisco | ios_xr | 6.5.25 | any |
| cisco | ios_xr | 6.5.26 | any |
| cisco | ios_xr | 6.5.28 | any |
| cisco | ios_xr | 6.5.29 | any |
| cisco | ios_xr | 6.5.31 | any |
| cisco | ios_xr | 6.5.32 | any |
| cisco | ios_xr | 6.5.33 | any |
| cisco | ios_xr | 6.5.90 | any |
| cisco | ios_xr | 6.5.92 | any |
| cisco | ios_xr | 6.5.93 | any |
| cisco | ios_xr | 6.6.1 | any |
| cisco | ios_xr | 6.6.2 | any |
| cisco | ios_xr | 6.6.3 | any |
| cisco | ios_xr | 6.6.4 | any |
| cisco | ios_xr | 6.6.11 | any |
| cisco | ios_xr | 6.6.12 | any |
| cisco | ios_xr | 6.6.25 | any |
| cisco | ios_xr | 6.7.1 | any |
| cisco | ios_xr | 6.7.2 | any |
| cisco | ios_xr | 6.7.3 | any |
| cisco | ios_xr | 6.7.4 | any |
| cisco | ios_xr | 6.7.35 | any |
| cisco | ios_xr | 6.8.1 | any |
| cisco | ios_xr | 6.8.2 | any |
| cisco | ios_xr | 6.9.1 | any |
| cisco | ios_xr | 6.9.2 | any |
| cisco | ios_xr | 7.0.0 | any |
| cisco | ios_xr | 7.0.1 | any |
| cisco | ios_xr | 7.0.2 | any |
| cisco | ios_xr | 7.0.11 | any |
| cisco | ios_xr | 7.0.12 | any |
| cisco | ios_xr | 7.0.14 | any |
| cisco | ios_xr | 7.0.90 | any |
| cisco | ios_xr | 7.1.1 | any |
| cisco | ios_xr | 7.1.2 | any |
| cisco | ios_xr | 7.1.3 | any |
| cisco | ios_xr | 7.1.15 | any |
| cisco | ios_xr | 7.1.25 | any |
| cisco | ios_xr | 7.2.0 | any |
| cisco | ios_xr | 7.2.1 | any |
| cisco | ios_xr | 7.2.2 | any |
| cisco | ios_xr | 7.2.12 | any |
| cisco | ios_xr | 7.3.1 | any |
| cisco | ios_xr | 7.3.2 | any |
| cisco | ios_xr | 7.3.3 | any |
| cisco | ios_xr | 7.3.4 | any |
| cisco | ios_xr | 7.3.5 | any |
| cisco | ios_xr | 7.3.6 | any |
| cisco | ios_xr | 7.3.15 | any |
| cisco | ios_xr | 7.3.16 | any |
| cisco | ios_xr | 7.3.27 | any |
| cisco | ios_xr | 7.4.1 | any |
| cisco | ios_xr | 7.4.2 | any |
| cisco | ios_xr | 7.4.15 | any |
| cisco | ios_xr | 7.4.16 | any |
| cisco | ios_xr | 7.5.1 | any |
| cisco | ios_xr | 7.5.2 | any |
| cisco | ios_xr | 7.5.3 | any |
| cisco | ios_xr | 7.5.4 | any |
| cisco | ios_xr | 7.5.5 | any |
| cisco | ios_xr | 7.5.12 | any |
| cisco | ios_xr | 7.5.52 | any |
| cisco | ios_xr | 7.6.1 | any |
| cisco | ios_xr | 7.6.2 | any |
| cisco | ios_xr | 7.6.3 | any |
| cisco | ios_xr | 7.6.15 | any |
| cisco | ios_xr | 7.7.1 | any |
| cisco | ios_xr | 7.7.2 | any |
| cisco | ios_xr | 7.7.21 | any |
| cisco | ios_xr | 7.8.1 | any |
| cisco | ios_xr | 7.8.2 | any |
| cisco | ios_xr | 7.8.12 | any |
| cisco | ios_xr | 7.8.22 | any |
| cisco | ios_xr | 7.9.1 | any |
| cisco | ios_xr | 7.9.2 | any |
| cisco | ios_xr | 7.9.21 | any |
| cisco | ios_xr | 7.10.1 | any |
| cisco | ios_xr | 7.10.2 | any |
| cisco | ios_xr | 7.11.1 | any |
| cisco | ios_xr | 7.11.2 | any |
| cisco | ios_xr | 24.1.1 | any |
| cisco | ios_xr | 24.1.2 | any |
| cisco | ios_xr | 24.2.1 | any |
| cisco | ios_xr | 24.2.11 | any |
| cisco | network_services_orchestrator | 4.4.1 | any |
| cisco | network_services_orchestrator | 4.5.1 | any |
| cisco | network_services_orchestrator | 4.7.1 | any |
| cisco | network_services_orchestrator | 4.7.3 | any |
| cisco | network_services_orchestrator | 5.1.1.1 | any |
| cisco | network_services_orchestrator | 5.1.1.3 | any |
| cisco | network_services_orchestrator | 5.1.2 | any |
| cisco | network_services_orchestrator | 5.1.4.3 | any |
| cisco | network_services_orchestrator | 5.2.0.3 | any |
| cisco | network_services_orchestrator | 5.2.0.4 | any |
| cisco | network_services_orchestrator | 5.2.1 | any |
| cisco | network_services_orchestrator | 5.2.1.1 | any |
| cisco | network_services_orchestrator | 5.2.3.2 | any |
| cisco | network_services_orchestrator | 5.3.1 | any |
| cisco | network_services_orchestrator | 5.3.4.3 | any |
| cisco | network_services_orchestrator | 5.4 | any |
| cisco | network_services_orchestrator | 5.4.0.1 | any |
| cisco | network_services_orchestrator | 5.4.0.2 | any |
| cisco | network_services_orchestrator | 5.4.1 | any |
| cisco | network_services_orchestrator | 5.4.1.1 | any |
| cisco | network_services_orchestrator | 5.4.2 | any |
| cisco | network_services_orchestrator | 5.4.2.1 | any |
| cisco | network_services_orchestrator | 5.4.2.2 | any |
| cisco | network_services_orchestrator | 5.4.3 | any |
| cisco | network_services_orchestrator | 5.4.3.1 | any |
| cisco | network_services_orchestrator | 5.4.3.2 | any |
| cisco | network_services_orchestrator | 5.4.3.3 | any |
| cisco | network_services_orchestrator | 5.4.3.4 | any |
| cisco | network_services_orchestrator | 5.4.4 | any |
| cisco | network_services_orchestrator | 5.4.4.1 | any |
| cisco | network_services_orchestrator | 5.4.4.2 | any |
| cisco | network_services_orchestrator | 5.4.4.3 | any |
| cisco | network_services_orchestrator | 5.4.5 | any |
| cisco | network_services_orchestrator | 5.4.5.1 | any |
| cisco | network_services_orchestrator | 5.4.5.2 | any |
| cisco | network_services_orchestrator | 5.4.6 | any |
| cisco | network_services_orchestrator | 5.4.7 | any |
| cisco | network_services_orchestrator | 5.4.7.1 | any |
| cisco | network_services_orchestrator | 5.5 | any |
| cisco | network_services_orchestrator | 5.5.1 | any |
| cisco | network_services_orchestrator | 5.5.2 | any |
| cisco | network_services_orchestrator | 5.5.2.1 | any |
| cisco | network_services_orchestrator | 5.5.2.2 | any |
| cisco | network_services_orchestrator | 5.5.2.3 | any |
| cisco | network_services_orchestrator | 5.5.2.4 | any |
| cisco | network_services_orchestrator | 5.5.2.5 | any |
| cisco | network_services_orchestrator | 5.5.2.6 | any |
| cisco | network_services_orchestrator | 5.5.2.7 | any |
| cisco | network_services_orchestrator | 5.5.2.8 | any |
| cisco | network_services_orchestrator | 5.5.2.9 | any |
| cisco | network_services_orchestrator | 5.5.2.10 | any |
| cisco | network_services_orchestrator | 5.5.2.11 | any |
| cisco | network_services_orchestrator | 5.5.2.12 | any |
| cisco | network_services_orchestrator | 5.5.3 | any |
| cisco | network_services_orchestrator | 5.5.3.1 | any |
| cisco | network_services_orchestrator | 5.5.4 | any |
| cisco | network_services_orchestrator | 5.5.4.1 | any |
| cisco | network_services_orchestrator | 5.5.5 | any |
| cisco | network_services_orchestrator | 5.5.6 | any |
| cisco | network_services_orchestrator | 5.5.6.1 | any |
| cisco | network_services_orchestrator | 5.5.7 | any |
| cisco | network_services_orchestrator | 5.5.8 | any |
| cisco | network_services_orchestrator | 5.5.9 | any |
| cisco | network_services_orchestrator | 5.5.10 | any |
| cisco | network_services_orchestrator | 5.6 | any |
| cisco | network_services_orchestrator | 5.6.1 | any |
| cisco | network_services_orchestrator | 5.6.2 | any |
| cisco | network_services_orchestrator | 5.6.3 | any |
| cisco | network_services_orchestrator | 5.6.3.1 | any |
| cisco | network_services_orchestrator | 5.6.4 | any |
| cisco | network_services_orchestrator | 5.6.5 | any |
| cisco | network_services_orchestrator | 5.6.6 | any |
| cisco | network_services_orchestrator | 5.6.6.1 | any |
| cisco | network_services_orchestrator | 5.6.7 | any |
| cisco | network_services_orchestrator | 5.6.7.1 | any |
| cisco | network_services_orchestrator | 5.6.7.2 | any |
| cisco | network_services_orchestrator | 5.6.8 | any |
| cisco | network_services_orchestrator | 5.6.8.1 | any |
| cisco | network_services_orchestrator | 5.6.9 | any |
| cisco | network_services_orchestrator | 5.6.10 | any |
| cisco | network_services_orchestrator | 5.6.11 | any |
| cisco | network_services_orchestrator | 5.6.12 | any |
| cisco | network_services_orchestrator | 5.6.13 | any |
| cisco | network_services_orchestrator | 5.6.14 | any |
| cisco | network_services_orchestrator | 5.6.14.1 | any |
| cisco | network_services_orchestrator | 5.7 | any |
| cisco | network_services_orchestrator | 5.7.1 | any |
| cisco | network_services_orchestrator | 5.7.1.1 | any |
| cisco | network_services_orchestrator | 5.7.2 | any |
| cisco | network_services_orchestrator | 5.7.2.1 | any |
| cisco | network_services_orchestrator | 5.7.3 | any |
| cisco | network_services_orchestrator | 5.7.4 | any |
| cisco | network_services_orchestrator | 5.7.5 | any |
| cisco | network_services_orchestrator | 5.7.5.1 | any |
| cisco | network_services_orchestrator | 5.7.6 | any |
| cisco | network_services_orchestrator | 5.7.6.1 | any |
| cisco | network_services_orchestrator | 5.7.6.2 | any |
| cisco | network_services_orchestrator | 5.7.6.3 | any |
| cisco | network_services_orchestrator | 5.7.7 | any |
| cisco | network_services_orchestrator | 5.7.8 | any |
| cisco | network_services_orchestrator | 5.7.8.1 | any |
| cisco | network_services_orchestrator | 5.7.9 | any |
| cisco | network_services_orchestrator | 5.7.9.1 | any |
| cisco | network_services_orchestrator | 5.7.10 | any |
| cisco | network_services_orchestrator | 5.7.10.1 | any |
| cisco | network_services_orchestrator | 5.7.10.2 | any |
| cisco | network_services_orchestrator | 5.7.11 | any |
| cisco | network_services_orchestrator | 5.7.12 | any |
| cisco | network_services_orchestrator | 5.7.13 | any |
| cisco | network_services_orchestrator | 5.7.14 | any |
| cisco | network_services_orchestrator | 5.7.15 | any |
| cisco | network_services_orchestrator | 5.7.15.1 | any |
| cisco | network_services_orchestrator | 5.7.17 | any |
| cisco | network_services_orchestrator | 5.8 | any |
| cisco | network_services_orchestrator | 5.8.1 | any |
| cisco | network_services_orchestrator | 5.8.2 | any |
| cisco | network_services_orchestrator | 5.8.2.1 | any |
| cisco | network_services_orchestrator | 5.8.3 | any |
| cisco | network_services_orchestrator | 5.8.4 | any |
| cisco | network_services_orchestrator | 5.8.5 | any |
| cisco | network_services_orchestrator | 5.8.6 | any |
| cisco | network_services_orchestrator | 5.8.7 | any |
| cisco | network_services_orchestrator | 5.8.8 | any |
| cisco | network_services_orchestrator | 5.8.9 | any |
| cisco | network_services_orchestrator | 5.8.10 | any |
| cisco | network_services_orchestrator | 5.8.11 | any |
| cisco | network_services_orchestrator | 5.8.12 | any |
| cisco | network_services_orchestrator | 5.8.13 | any |
| cisco | network_services_orchestrator | 6.0 | any |
| cisco | network_services_orchestrator | 6.0.1 | any |
| cisco | network_services_orchestrator | 6.0.1.1 | any |
| cisco | network_services_orchestrator | 6.0.2 | any |
| cisco | network_services_orchestrator | 6.0.3 | any |
| cisco | network_services_orchestrator | 6.0.4 | any |
| cisco | network_services_orchestrator | 6.0.5 | any |
| cisco | network_services_orchestrator | 6.0.6 | any |
| cisco | network_services_orchestrator | 6.0.7 | any |
| cisco | network_services_orchestrator | 6.0.8 | any |
| cisco | network_services_orchestrator | 6.0.9 | any |
| cisco | network_services_orchestrator | 6.0.10 | any |
| cisco | network_services_orchestrator | 6.0.11 | any |
| cisco | network_services_orchestrator | 6.0.12 | any |
| cisco | network_services_orchestrator | 6.1 | any |
| cisco | network_services_orchestrator | 6.1.1 | any |
| cisco | network_services_orchestrator | 6.1.2 | any |
| cisco | network_services_orchestrator | 6.1.2.1 | any |
| cisco | network_services_orchestrator | 6.1.3 | any |
| cisco | network_services_orchestrator | 6.1.3.1 | any |
| cisco | network_services_orchestrator | 6.1.3.2 | any |
| cisco | network_services_orchestrator | 6.1.4 | any |
| cisco | network_services_orchestrator | 6.1.5 | any |
| cisco | network_services_orchestrator | 6.1.6 | any |
| cisco | network_services_orchestrator | 6.1.6.1 | any |
| cisco | network_services_orchestrator | 6.1.7 | any |
| cisco | network_services_orchestrator | 6.1.7.1 | any |
| cisco | network_services_orchestrator | 6.1.8 | any |
| cisco | network_services_orchestrator | 6.1.10 | any |
| cisco | network_services_orchestrator | 6.1.11 | any |
| cisco | network_services_orchestrator | 6.1.11.1 | any |
| cisco | network_services_orchestrator | 6.1.11.2 | any |
| cisco | network_services_orchestrator | 6.1.12 | any |
| cisco | network_services_orchestrator | 6.2 | any |
| cisco | network_services_orchestrator | 6.2.2 | any |
| cisco | small_business_rv_series_router_firmware | 1.0.00.29 | any |
| cisco | small_business_rv_series_router_firmware | 1.0.00.33 | any |
| cisco | small_business_rv_series_router_firmware | 1.0.01.16 | any |
| cisco | small_business_rv_series_router_firmware | 1.0.01.17 | any |
| cisco | small_business_rv_series_router_firmware | 1.0.01.18 | any |
| cisco | small_business_rv_series_router_firmware | 1.0.01.20 | any |
| cisco | small_business_rv_series_router_firmware | 1.0.02.16 | any |
| cisco | small_business_rv_series_router_firmware | 1.0.03.15 | any |
| cisco | small_business_rv_series_router_firmware | 1.0.03.16 | any |
| cisco | small_business_rv_series_router_firmware | 1.0.03.17 | any |
| cisco | small_business_rv_series_router_firmware | 1.0.03.18 | any |
| cisco | small_business_rv_series_router_firmware | 1.0.03.19 | any |
| cisco | small_business_rv_series_router_firmware | 1.0.03.20 | any |
| cisco | small_business_rv_series_router_firmware | 1.0.03.21 | any |
| cisco | small_business_rv_series_router_firmware | 1.0.03.22 | any |
| cisco | small_business_rv_series_router_firmware | 1.0.03.24 | any |
| cisco | small_business_rv_series_router_firmware | 1.0.03.26 | any |
| cisco | small_business_rv_series_router_firmware | 1.0.03.27 | any |
| cisco | small_business_rv_series_router_firmware | 1.0.03.28 | any |
| cisco | small_business_rv_series_router_firmware | 1.0.03.29 | any |
References 1
- sec.cloudapps.cisco.com https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nso-auth-bypass-QnTEesp
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.