This vulnerability is due to insufficient image verification. An attacker could exploit this vulnerability by manipulating the boot parameters for image verification during the iPXE boot process on an affected device. A successful exploit could allow the attacker to boot an unverified software image on the affected device.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Cisco
Subscribe
|
8201
Subscribe
8202
Subscribe
8208
Subscribe
8212
Subscribe
8218
Subscribe
8804
Subscribe
8808
Subscribe
8812
Subscribe
8818
Subscribe
8831
Subscribe
Asr 9000
Subscribe
Asr 9000v
Subscribe
Asr 9001
Subscribe
Asr 9006
Subscribe
Asr 9010
Subscribe
Asr 9901
Subscribe
Asr 9902
Subscribe
Asr 9903
Subscribe
Asr 9904
Subscribe
Asr 9906
Subscribe
Asr 9910
Subscribe
Asr 9912
Subscribe
Asr 9920
Subscribe
Asr 9922
Subscribe
Ios Xr
Subscribe
Ios Xr Software
Subscribe
Ncs 1001
Subscribe
Ncs 1002
Subscribe
Ncs 1004
Subscribe
Ncs 4009
Subscribe
Ncs 4016
Subscribe
Ncs 4201
Subscribe
Ncs 4202
Subscribe
Ncs 4206
Subscribe
Ncs 4216
Subscribe
Ncs 5001
Subscribe
Ncs 5002
Subscribe
Ncs 5011
Subscribe
Ncs 540
Subscribe
Ncs 5500
Subscribe
Ncs 5501
Subscribe
Ncs 5502
Subscribe
Ncs 5504
Subscribe
Ncs 5508
Subscribe
Ncs 5516
Subscribe
Ncs 560
Subscribe
Ncs 560-4
Subscribe
Ncs 560-7
Subscribe
Ncs 57b1-5dse-sys
Subscribe
Ncs 57b1-6d24-sys
Subscribe
Ncs 57c1-48q6-sys
Subscribe
Ncs 57c3-mod-sys
Subscribe
Ncs 57c3-mods-sys
Subscribe
|
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-24415 | A vulnerability in the iPXE boot function of Cisco IOS XR software could allow an authenticated, local attacker to install an unverified software image on an affected device. This vulnerability is due to insufficient image verification. An attacker could exploit this vulnerability by manipulating the boot parameters for image verification during the iPXE boot process on an affected device. A successful exploit could allow the attacker to boot an unverified software image on the affected device. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 17 Dec 2025 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
ssvc
|
Wed, 23 Oct 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cisco ios Xr Software
|
|
| CPEs | cpe:2.3:o:cisco:ios_xr_software:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cisco ios Xr Software
|
|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2025-12-16T18:23:20.640Z
Reserved: 2022-10-27T18:47:50.370Z
Link: CVE-2023-20236
Updated: 2024-08-02T09:05:35.905Z
Status : Modified
Published: 2023-09-13T17:15:09.607
Modified: 2024-11-21T07:40:57.700
Link: CVE-2023-20236
No data.
OpenCVE Enrichment
No data.
EUVD