A vulnerability in the storage method of the PON Controller configuration file could allow an authenticated, local attacker with low privileges to obtain the MongoDB credentials.
This vulnerability is due to improper storage of the unencrypted database credentials on the device that is running Cisco IOS XR Software. An attacker could exploit this vulnerability by accessing the configuration files on an affected system. A successful exploit could allow the attacker to view MongoDB credentials.
Metrics
Affected Vendors & Products
References
History
Thu, 03 Oct 2024 02:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-522 | |
CPEs | cpe:2.3:o:cisco:ios_xr:24.1.1:*:*:*:*:*:*:* cpe:2.3:o:cisco:ios_xr:24.1.2:*:*:*:*:*:*:* cpe:2.3:o:cisco:ios_xr:24.2.11:*:*:*:*:*:*:* cpe:2.3:o:cisco:ios_xr:24.2.1:*:*:*:*:*:*:* cpe:2.3:o:cisco:ios_xr:24.3.1:*:*:*:*:*:*:* |
Wed, 11 Sep 2024 21:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Cisco
Cisco ios Xr |
|
CPEs | cpe:2.3:o:cisco:ios_xr:*:*:*:*:*:*:*:* | |
Vendors & Products |
Cisco
Cisco ios Xr |
|
Metrics |
ssvc
|
Wed, 11 Sep 2024 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability in the storage method of the PON Controller configuration file could allow an authenticated, local attacker with low privileges to obtain the MongoDB credentials. This vulnerability is due to improper storage of the unencrypted database credentials on the device that is running Cisco IOS XR Software. An attacker could exploit this vulnerability by accessing the configuration files on an affected system. A successful exploit could allow the attacker to view MongoDB credentials. | |
Title | Cisco Routed Passive Optical Network Cleartext Password Vulnerability | |
Weaknesses | CWE-256 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: cisco
Published: 2024-09-11T16:39:06.449Z
Updated: 2024-09-11T20:12:26.719Z
Reserved: 2023-11-08T15:08:07.685Z
Link: CVE-2024-20489
Vulnrichment
Updated: 2024-09-11T20:12:12.959Z
NVD
Status : Analyzed
Published: 2024-09-11T17:15:13.393
Modified: 2024-10-03T01:40:11.637
Link: CVE-2024-20489
Redhat
No data.