NA

CVE-2023-20236

Published: 13/09/2023 Updated: 25/01/2024
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

A vulnerability in the iPXE boot function of Cisco IOS XR software could allow an authenticated, local malicious user to install an unverified software image on an affected device. This vulnerability is due to insufficient image verification. An attacker could exploit this vulnerability by manipulating the boot parameters for image verification during the iPXE boot process on an affected device. A successful exploit could allow the malicious user to boot an unverified software image on the affected device.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ios_xr

Vendor Advisories

A vulnerability in the iPXE boot function of Cisco IOS XR software could allow an authenticated, local attacker to install an unverified software image on an affected device This vulnerability is due to insufficient image verification An attacker could exploit this vulnerability by manipulating the boot parameters for image verification during th ...