Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-20135
HistorySep 13, 2023 - 5:15 p.m.

Race condition

2023-09-1317:15:00
PRIOn knowledge base
www.prio-n.com
8
cisco ios xr
software
image verification
vulnerability
arbitrary code execution
race condition
time-of-check
time-of-use
toctou
install operation
iso image
exploit
nvd

7 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

A vulnerability in Cisco IOS XR Software image verification checks could allow an authenticated, local attacker to execute arbitrary code on the underlying operating system.

This vulnerability is due to a time-of-check, time-of-use (TOCTOU) race condition when an install query regarding an ISO image is performed during an install operation that uses an ISO image. An attacker could exploit this vulnerability by modifying an ISO image and then carrying out install requests in parallel. A successful exploit could allow the attacker to execute arbitrary code on an affected device.

CPENameOperatorVersion
ios_xrge7.7
ios_xrlt7.10.1
ios_xrge7.5.2
ios_xrlt7.6

7 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

Related for PRION:CVE-2023-20135