A vulnerability in the iPXE boot function of Cisco IOS XR software could allow an authenticated, local attacker to install an unverified software image on an affected device. This vulnerability is due to insufficient image verification. An attacker could exploit this vulnerability by manipulating the boot parameters for image verification during the iPXE boot process on an affected device. A successful exploit could allow the attacker to boot an unverified software image on the affected device.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published: 2023-09-13T16:39:19.418Z

Updated: 2024-08-07T19:50:10.951Z

Reserved: 2022-10-27T18:47:50.370Z

Link: CVE-2023-20236

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-09-13T17:15:09.607

Modified: 2024-01-25T17:15:39.850

Link: CVE-2023-20236

cve-icon Redhat

No data.