A vulnerability in the storage method of the PON Controller configuration file could allow an authenticated, local attacker with low privileges to obtain the MongoDB credentials. This vulnerability is due to improper storage of the unencrypted database credentials on the device that is running Cisco IOS XR Software. An attacker could exploit this vulnerability by accessing the configuration files on an affected system. A successful exploit could allow the attacker to view MongoDB credentials.
History

Wed, 11 Sep 2024 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco ios Xr
CPEs cpe:2.3:o:cisco:ios_xr:*:*:*:*:*:*:*:*
Vendors & Products Cisco
Cisco ios Xr
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 11 Sep 2024 17:00:00 +0000

Type Values Removed Values Added
Description A vulnerability in the storage method of the PON Controller configuration file could allow an authenticated, local attacker with low privileges to obtain the MongoDB credentials. This vulnerability is due to improper storage of the unencrypted database credentials on the device that is running Cisco IOS XR Software. An attacker could exploit this vulnerability by accessing the configuration files on an affected system. A successful exploit could allow the attacker to view MongoDB credentials.
Title Cisco Routed Passive Optical Network Cleartext Password Vulnerability
Weaknesses CWE-256
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published: 2024-09-11T16:39:06.449Z

Updated: 2024-09-11T20:12:26.719Z

Reserved: 2023-11-08T15:08:07.685Z

Link: CVE-2024-20489

cve-icon Vulnrichment

Updated: 2024-09-11T20:12:12.959Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-09-11T17:15:13.393

Modified: 2024-09-12T12:35:54.013

Link: CVE-2024-20489

cve-icon Redhat

No data.