{ "data_version": "4.0", "data_type": "CVE", "data_format": "MITRE", "CVE_data_meta": { "ID": "CVE-2024-20286", "ASSIGNER": "psirt@cisco.com", "STATE": "PUBLIC" }, "description": { "description_data": [ { "lang": "eng", "value": "A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to escape the Python sandbox and gain unauthorized access to the underlying operating system of the device.\r\n\r\nThe vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by manipulating specific functions within the Python interpreter. A successful exploit could allow an attacker to escape the Python sandbox and execute arbitrary commands on the underlying operating system with the privileges of the authenticated user. \r\nNote: An attacker must be authenticated with Python execution privileges to exploit these vulnerabilities. For more information regarding Python execution privileges, see product-specific documentation, such as the section of the Cisco Nexus 9000 Series NX-OS Programmability Guide." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "Protection Mechanism Failure", "cweId": "CWE-693" } ] } ] }, "affects": { "vendor": { "vendor_data": [ { "vendor_name": "Cisco", "product": { "product_data": [ { "product_name": "Cisco NX-OS Software", "version": { "version_data": [ { "version_affected": "=", "version_value": "8.2(5)" }, { "version_affected": "=", "version_value": "7.3(5)D1(1)" }, { "version_affected": "=", "version_value": "8.4(2)" }, { "version_affected": "=", "version_value": "6.2(2)" }, { "version_affected": "=", "version_value": "8.4(3)" }, { "version_affected": "=", "version_value": "9.2(3)" }, { "version_affected": "=", "version_value": "7.0(3)I5(2)" }, { "version_affected": "=", "version_value": "8.2(1)" }, { "version_affected": "=", "version_value": "6.0(2)A8(7a)" }, { "version_affected": "=", "version_value": "7.0(3)I4(5)" }, { "version_affected": "=", "version_value": "6.0(2)A6(1)" }, { "version_affected": "=", "version_value": "7.3(1)D1(1)" }, { "version_affected": "=", "version_value": "6.2(14a)" }, { "version_affected": "=", "version_value": "7.0(3)I4(6)" }, { "version_affected": "=", "version_value": "7.0(3)I4(3)" }, { "version_affected": "=", "version_value": "9.2(2v)" }, { "version_affected": "=", "version_value": "6.0(2)A6(5b)" }, { "version_affected": "=", "version_value": "7.3(0)D1(1)" }, { "version_affected": "=", "version_value": "6.2(17a)" }, { "version_affected": "=", "version_value": "7.0(3)I4(7)" }, { "version_affected": "=", "version_value": "6.0(2)U6(1a)" }, { "version_affected": "=", "version_value": "7.0(3)I4(1)" }, { "version_affected": "=", "version_value": "7.0(3)I4(8)" }, { "version_affected": "=", "version_value": "7.0(3)I4(2)" }, { "version_affected": "=", "version_value": "7.0(3)IM3(1)" }, { "version_affected": "=", "version_value": "6.0(2)U6(5a)" }, { "version_affected": "=", "version_value": "6.0(2)A8(11)" }, { "version_affected": "=", "version_value": "6.0(2)A6(4a)" }, { "version_affected": "=", "version_value": "6.2(9)" }, { "version_affected": "=", "version_value": "6.2(5)" }, { "version_affected": "=", "version_value": "7.3(4)D1(1)" }, { "version_affected": "=", "version_value": "6.2(20)" }, { "version_affected": "=", "version_value": "9.2(1)" }, { "version_affected": "=", "version_value": "9.2(2t)" }, { "version_affected": "=", "version_value": "9.2(3y)" }, { "version_affected": "=", "version_value": "7.0(3)I4(1t)" }, { "version_affected": "=", "version_value": "6.0(2)U6(5c)" }, { "version_affected": "=", "version_value": "6.0(2)A6(4)" }, { "version_affected": "=", "version_value": "7.0(3)I7(6z)" }, { "version_affected": "=", "version_value": "9.3(2)" }, { "version_affected": "=", "version_value": "7.3(1)DY(1)" }, { "version_affected": "=", "version_value": "7.0(3)F3(3)" }, { "version_affected": "=", "version_value": "6.0(2)U6(6)" }, { "version_affected": "=", "version_value": "6.2(29)" }, { "version_affected": "=", "version_value": "7.0(3)I7(3z)" }, { "version_affected": "=", "version_value": "7.0(3)IM7(2)" }, { "version_affected": "=", "version_value": "6.0(2)A8(11b)" }, { "version_affected": "=", "version_value": "6.2(9a)" }, { "version_affected": "=", "version_value": "7.0(3)I7(5a)" }, { "version_affected": "=", "version_value": "6.2(11d)" }, { "version_affected": "=", "version_value": "8.1(1)" }, { "version_affected": "=", "version_value": "7.0(3)I6(1)" }, { "version_affected": "=", "version_value": "6.0(2)U6(10)" }, { "version_affected": "=", "version_value": "7.2(2)D1(2)" }, { "version_affected": "=", "version_value": "7.0(3)IM3(2)" }, { "version_affected": "=", "version_value": "6.0(2)A6(8)" }, { "version_affected": "=", "version_value": "8.2(2)" }, { "version_affected": "=", "version_value": "6.0(2)U6(1)" }, { "version_affected": "=", "version_value": "7.0(3)I5(3b)" }, { "version_affected": "=", "version_value": "8.3(2)" }, { "version_affected": "=", "version_value": "6.0(2)A6(2a)" }, { "version_affected": "=", "version_value": "6.2(27)" }, { "version_affected": "=", "version_value": "7.3(2)D1(3a)" }, { "version_affected": "=", "version_value": "6.0(2)U6(7)" }, { "version_affected": "=", "version_value": "9.2(4)" }, { "version_affected": "=", "version_value": "7.0(3)IM3(2a)" }, { "version_affected": "=", "version_value": "6.2(8b)" }, { "version_affected": "=", "version_value": "6.0(2)A8(10)" }, { "version_affected": "=", "version_value": "6.2(13)" }, { "version_affected": "=", "version_value": "6.0(2)A8(2)" }, { "version_affected": "=", "version_value": "7.0(3)IC4(4)" }, { "version_affected": "=", "version_value": "6.2(1)" }, { "version_affected": "=", "version_value": "8.1(2)" }, { "version_affected": "=", "version_value": "6.0(2)A6(3)" }, { "version_affected": "=", "version_value": "6.0(2)U6(5b)" }, { "version_affected": "=", "version_value": "7.0(3)F3(3c)" }, { "version_affected": "=", "version_value": "7.3(3)D1(1)" }, { "version_affected": "=", "version_value": "7.0(3)F3(1)" }, { "version_affected": "=", "version_value": "6.0(2)U6(5)" }, { "version_affected": "=", "version_value": "7.0(3)F3(5)" }, { "version_affected": "=", "version_value": "8.2(3)" }, { "version_affected": "=", "version_value": "6.0(2)A6(7)" }, { "version_affected": "=", "version_value": "7.0(3)I7(2)" }, { "version_affected": "=", "version_value": "6.2(5a)" }, { "version_affected": "=", "version_value": "6.2(18)" }, { "version_affected": "=", "version_value": "6.0(2)A6(5)" }, { "version_affected": "=", "version_value": "7.0(3)IM3(2b)" }, { "version_affected": "=", "version_value": "6.0(2)U6(4a)" }, { "version_affected": "=", "version_value": "7.0(3)I5(3)" }, { "version_affected": "=", "version_value": "7.0(3)I7(3)" }, { "version_affected": "=", "version_value": "6.0(2)A8(6)" }, { "version_affected": "=", "version_value": "7.0(3)I6(2)" }, { "version_affected": "=", "version_value": "8.3(1)" }, { "version_affected": "=", "version_value": "6.2(3)" }, { "version_affected": "=", "version_value": "6.2(22)" }, { "version_affected": "=", "version_value": "8.4(1)" }, { "version_affected": "=", "version_value": "8.1(1b)" }, { "version_affected": "=", "version_value": "7.2(2)D1(4)" }, { "version_affected": "=", "version_value": "6.0(2)A8(5)" }, { "version_affected": "=", "version_value": "7.3(0)DX(1)" }, { "version_affected": "=", "version_value": "7.3(2)D1(1)" }, { "version_affected": "=", "version_value": "6.0(2)U6(8)" }, { "version_affected": "=", "version_value": "7.0(3)IM3(3)" }, { "version_affected": "=", "version_value": "9.3(1)" }, { "version_affected": "=", "version_value": "6.0(2)U6(2)" }, { "version_affected": "=", "version_value": "6.2(9b)" }, { "version_affected": "=", "version_value": "6.0(2)A8(7)" }, { "version_affected": "=", "version_value": "7.0(3)I7(6)" }, { "version_affected": "=", "version_value": "7.3(2)D1(2)" }, { "version_affected": "=", "version_value": "6.2(25)" }, { "version_affected": "=", "version_value": "6.0(2)U6(3a)" }, { "version_affected": "=", "version_value": "8.0(1)" }, { "version_affected": "=", "version_value": "6.0(2)A8(11a)" }, { "version_affected": "=", "version_value": "6.2(11e)" }, { "version_affected": "=", "version_value": "7.0(3)I4(8z)" }, { "version_affected": "=", "version_value": "6.2(11)" }, { "version_affected": "=", "version_value": "7.0(3)I4(9)" }, { "version_affected": "=", "version_value": "6.2(16)" }, { "version_affected": "=", "version_value": "6.2(19)" }, { "version_affected": "=", "version_value": "8.2(4)" }, { "version_affected": "=", "version_value": "6.2(2a)" }, { "version_affected": "=", "version_value": "7.2(2)D1(3)" }, { "version_affected": "=", "version_value": "7.0(3)I7(4)" }, { "version_affected": "=", "version_value": "7.0(3)I7(7)" }, { "version_affected": "=", "version_value": "6.2(5b)" }, { "version_affected": "=", "version_value": "7.3(0)DY(1)" }, { "version_affected": "=", "version_value": "6.0(2)A8(9)" }, { "version_affected": "=", "version_value": "6.0(2)A8(1)" }, { "version_affected": "=", "version_value": "7.2(1)D1(1)" }, { "version_affected": "=", "version_value": "6.2(15)" }, { "version_affected": "=", "version_value": "6.0(2)A6(6)" }, { "version_affected": "=", "version_value": "6.0(2)A8(10a)" }, { "version_affected": "=", "version_value": "7.0(3)I5(1)" }, { "version_affected": "=", "version_value": "9.3(1z)" }, { "version_affected": "=", "version_value": "9.2(2)" }, { "version_affected": "=", "version_value": "6.2(7)" }, { "version_affected": "=", "version_value": "6.2(9c)" }, { "version_affected": "=", "version_value": "7.0(3)F3(4)" }, { "version_affected": "=", "version_value": "6.2(6b)" }, { "version_affected": "=", "version_value": "7.0(3)I4(8b)" }, { "version_affected": "=", "version_value": "8.1(2a)" }, { "version_affected": "=", "version_value": "7.3(2)D1(3)" }, { "version_affected": "=", "version_value": "6.2(8)" }, { "version_affected": "=", "version_value": "6.0(2)A8(3)" }, { "version_affected": "=", "version_value": "6.2(11b)" }, { "version_affected": "=", "version_value": "7.0(3)I4(6t)" }, { "version_affected": "=", "version_value": "7.0(3)I5(3a)" }, { "version_affected": "=", "version_value": "8.1(1a)" }, { "version_affected": "=", "version_value": "6.2(13a)" }, { "version_affected": "=", "version_value": "6.0(2)A8(8)" }, { "version_affected": "=", "version_value": "7.0(3)I7(5)" }, { "version_affected": "=", "version_value": "7.0(3)F3(3a)" }, { "version_affected": "=", "version_value": "6.0(2)A8(4)" }, { "version_affected": "=", "version_value": "6.0(2)A6(3a)" }, { "version_affected": "=", "version_value": "6.0(2)A6(5a)" }, { "version_affected": "=", "version_value": "7.0(3)F2(1)" }, { "version_affected": "=", "version_value": "7.0(3)I4(8a)" }, { "version_affected": "=", "version_value": "6.0(2)U6(9)" }, { "version_affected": "=", "version_value": "7.0(3)F3(2)" }, { "version_affected": "=", "version_value": "6.0(2)U6(2a)" }, { "version_affected": "=", "version_value": "6.2(12)" }, { "version_affected": "=", "version_value": "6.2(17)" }, { "version_affected": "=", "version_value": "7.0(3)I4(4)" }, { "version_affected": "=", "version_value": "6.2(23)" }, { "version_affected": "=", "version_value": "6.2(13b)" }, { "version_affected": "=", "version_value": "6.0(2)U6(3)" }, { "version_affected": "=", "version_value": "6.2(10)" }, { "version_affected": "=", "version_value": "6.2(6a)" }, { "version_affected": "=", "version_value": "6.2(6)" }, { "version_affected": "=", "version_value": "6.2(14)" }, { "version_affected": "=", "version_value": "7.0(3)I7(1)" }, { "version_affected": "=", "version_value": "6.2(14b)" }, { "version_affected": "=", "version_value": "6.2(21)" }, { "version_affected": "=", "version_value": "7.2(2)D1(1)" }, { "version_affected": "=", "version_value": "7.0(3)F2(2)" }, { "version_affected": "=", "version_value": "7.0(3)IA7(2)" }, { "version_affected": "=", "version_value": "7.0(3)IA7(1)" }, { "version_affected": "=", "version_value": "6.0(2)A8(7b)" }, { "version_affected": "=", "version_value": "6.2(8a)" }, { "version_affected": "=", "version_value": "6.2(11c)" }, { "version_affected": "=", "version_value": "7.0(3)F1(1)" }, { "version_affected": "=", "version_value": "6.0(2)A6(1a)" }, { "version_affected": "=", "version_value": "7.2(0)D1(1)" }, { "version_affected": "=", "version_value": "6.0(2)A6(2)" }, { "version_affected": "=", "version_value": "6.0(2)A8(4a)" }, { "version_affected": "=", "version_value": "6.2(20a)" }, { "version_affected": "=", "version_value": "6.0(2)U6(4)" }, { "version_affected": "=", "version_value": "8.4(1a)" }, { "version_affected": "=", "version_value": "9.3(3)" }, { "version_affected": "=", "version_value": "7.3(2)D1(1d)" }, { "version_affected": "=", "version_value": "6.2(24)" }, { "version_affected": "=", "version_value": "6.2(31)" }, { "version_affected": "=", "version_value": "7.0(3)I7(8)" }, { "version_affected": "=", "version_value": "6.0(2)U6(10a)" }, { "version_affected": "=", "version_value": "9.3(4)" }, { "version_affected": "=", "version_value": "7.3(6)D1(1)" }, { "version_affected": "=", "version_value": "6.2(26)" }, { "version_affected": "=", "version_value": "8.2(6)" }, { "version_affected": "=", "version_value": "6.2(33)" }, { "version_affected": "=", "version_value": "9.3(5)" }, { "version_affected": "=", "version_value": "8.4(2a)" }, { "version_affected": "=", "version_value": "8.4(2b)" }, { "version_affected": "=", "version_value": "7.0(3)I7(9)" }, { "version_affected": "=", "version_value": "6.2(24a)" }, { "version_affected": "=", "version_value": "8.5(1)" }, { "version_affected": "=", "version_value": "9.3(6)" }, { "version_affected": "=", "version_value": "10.1(2)" }, { "version_affected": "=", "version_value": "10.1(1)" }, { "version_affected": "=", "version_value": "8.4(4)" }, { "version_affected": "=", "version_value": "7.3(7)D1(1)" }, { "version_affected": "=", "version_value": "8.4(2c)" }, { "version_affected": "=", "version_value": "9.3(5w)" }, { "version_affected": "=", "version_value": "8.2(7)" }, { "version_affected": "=", "version_value": "9.3(7)" }, { "version_affected": "=", "version_value": "9.3(7k)" }, { "version_affected": "=", "version_value": "7.0(3)I7(9w)" }, { "version_affected": "=", "version_value": "10.2(1)" }, { "version_affected": "=", "version_value": "7.3(8)D1(1)" }, { "version_affected": "=", "version_value": "9.3(7a)" }, { "version_affected": "=", "version_value": "8.2(7a)" }, { "version_affected": "=", "version_value": "9.3(8)" }, { "version_affected": "=", "version_value": "8.4(4a)" }, { "version_affected": "=", "version_value": "8.4(2d)" }, { "version_affected": "=", "version_value": "8.4(5)" }, { "version_affected": "=", "version_value": "7.0(3)I7(10)" }, { "version_affected": "=", "version_value": "8.2(8)" }, { "version_affected": "=", "version_value": "10.2(1q)" }, { "version_affected": "=", "version_value": "10.2(2)" }, { "version_affected": "=", "version_value": "9.3(9)" }, { "version_affected": "=", "version_value": "10.1(2t)" }, { "version_affected": "=", "version_value": "7.3(9)D1(1)" }, { "version_affected": "=", "version_value": "10.2(3)" }, { "version_affected": "=", "version_value": "8.4(6)" }, { "version_affected": "=", "version_value": "10.2(3t)" }, { "version_affected": "=", "version_value": "8.4(2e)" }, { "version_affected": "=", "version_value": "9.3(10)" }, { "version_affected": "=", "version_value": "10.2(2a)" }, { "version_affected": "=", "version_value": "9.2(1a)" }, { "version_affected": "=", "version_value": "8.2(9)" }, { "version_affected": "=", "version_value": "10.3(1)" }, { "version_affected": "=", "version_value": "10.2(4)" }, { "version_affected": "=", "version_value": "8.4(7)" }, { "version_affected": "=", "version_value": "10.3(2)" }, { "version_affected": "=", "version_value": "8.4(6a)" }, { "version_affected": "=", "version_value": "9.3(11)" }, { "version_affected": "=", "version_value": "10.3(3)" }, { "version_affected": "=", "version_value": "10.2(5)" }, { "version_affected": "=", "version_value": "9.4(1)" }, { "version_affected": "=", "version_value": "9.3(2a)" }, { "version_affected": "=", "version_value": "8.4(2f)" }, { "version_affected": "=", "version_value": "8.2(10)" }, { "version_affected": "=", "version_value": "9.3(12)" }, { "version_affected": "=", "version_value": "10.2(3v)" }, { "version_affected": "=", "version_value": "10.4(1)" }, { "version_affected": "=", "version_value": "8.4(8)" }, { "version_affected": "=", "version_value": "10.3(99w)" }, { "version_affected": "=", "version_value": "10.2(6)" }, { "version_affected": "=", "version_value": "10.3(3w)" }, { "version_affected": "=", "version_value": "10.3(99x)" }, { "version_affected": "=", "version_value": "10.3(3o)" }, { "version_affected": "=", "version_value": "8.4(9)" }, { "version_affected": "=", "version_value": "10.3(4)" }, { "version_affected": "=", "version_value": "10.3(3p)" }, { "version_affected": "=", "version_value": "10.3(4a)" }, { "version_affected": "=", "version_value": "9.4(1a)" }, { "version_affected": "=", "version_value": "10.4(2)" }, { "version_affected": "=", "version_value": "10.3(3q)" }, { "version_affected": "=", "version_value": "9.3(13)" }, { "version_affected": "=", "version_value": "10.2(7)" }, { "version_affected": "=", "version_value": "10.3(3x)" }, { "version_affected": "=", "version_value": "10.3(4g)" }, { "version_affected": "=", "version_value": "10.3(3r)" } ] } } ] } } ] } }, "references": { "reference_data": [ { "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxos-psbe-ce-YvbTn5du", "refsource": "MISC", "name": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxos-psbe-ce-YvbTn5du" }, { "url": "https://www.cisco.com/c/en/us/td/docs/dcn/nx-os/nexus9000/105x/programmability/cisco-nexus-9000-series-nx-os-programmability-guide-105x/m-n9k-python-api-101x.html?bookSearch=true#concept_A2CFF094ADCB414C983EA06AD8E9A410", "refsource": "MISC", "name": "https://www.cisco.com/c/en/us/td/docs/dcn/nx-os/nexus9000/105x/programmability/cisco-nexus-9000-series-nx-os-programmability-guide-105x/m-n9k-python-api-101x.html?bookSearch=true#concept_A2CFF094ADCB414C983EA06AD8E9A410" } ] }, "source": { "advisory": "cisco-sa-nxos-psbe-ce-YvbTn5du", "discovery": "INTERNAL", "defects": [ "CSCwh77781" ] }, "exploit": [ { "lang": "en", "value": "The Cisco Product Security Incident Response Team (PSIRT) is not aware of any public announcements or malicious use of the vulnerabilities that are described in this advisory." } ], "impact": { "cvss": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L", "baseScore": 5.3, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "LOW" } ] } }