CVE-2024-20306
A vulnerability in the Unified Threat Defense (UTD) configuration CLI of Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying host operating system. To exploit this vulnerability, an attacker must have level 15 privileges on the affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by submitting a crafted CLI command to an affected device. A successful exploit could allow the attacker to execute arbitrary commands as root on the underlying operating system.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
- EPSS probability
- 0.19%
- CWE
- CWE-233
- Published
- 2024-03-27
- Last modified
- 2026-03-13
Affected products
- Cisco Cisco IOS XE Software
- Cisco Cisco IOS XE Software
- Cisco Cisco IOS XE Software
- Cisco Cisco IOS XE Software
- Cisco Cisco IOS XE Software
- Cisco Cisco IOS XE Software
- Cisco Cisco IOS XE Software
- Cisco Cisco IOS XE Software
Weakness type
Related vulnerabilities
- CVE-2026-0515 — Insufficient parameter validation in the QNX Neutrino kernel impacts versions of the QNX Software Development Platform and QNX OS for Safety
- CVE-2026-32998 — This vulnerability in Veeam Service Provider Console allows for remote code execution.
- CVE-2026-33585 — Arqit SKA-Platform Improper Handling of Parameters Vulnerability
- CVE-2018-25233 — WebDrive 18.00.5057 Denial of Service via Secure WebDAV
- CVE-2026-2370 — Improper Handling of Parameters in GitLab
- CVE-2023-20514 — Improper handling of parameters in the AMD Secure Processor (ASP) could allow a privileged attacker...
- CVE-2025-55080 — Improper Parameter Check in ThreadX Syscall Implementation
- CVE-2025-55078 — Incomplete validation of kernel object pointers in system calls