CVE-2024-20381

A vulnerability in the JSON-RPC API feature in Cisco Crosswork Network Services Orchestrator (NSO) and ConfD that is used by the web-based management interfaces of Cisco Optical Site Manager and Cisco RV340 Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to modify the configuration of an affected application or device. 

This vulnerability is due to improper authorization checks on the API. An attacker with privileges sufficient to access the affected application or device could exploit this vulnerability by sending malicious requests to the JSON-RPC API. A successful exploit could allow the attacker to make unauthorized modifications to the configuration of the affected application or device, including creating new user accounts or elevating their own privileges on an affected system.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
ciscoCNA
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 47%
VendorProductVersion
ciscoios_xr
6.5.1
ciscoios_xr
6.5.2
ciscoios_xr
6.5.3
ciscoios_xr
6.5.15
ciscoios_xr
6.5.25
ciscoios_xr
6.5.26
ciscoios_xr
6.5.28
ciscoios_xr
6.5.29
ciscoios_xr
6.5.31
ciscoios_xr
6.5.32
ciscoios_xr
6.5.33
ciscoios_xr
6.5.90
ciscoios_xr
6.5.92
ciscoios_xr
6.5.93
ciscoios_xr
6.6.1
ciscoios_xr
6.6.2
ciscoios_xr
6.6.3
ciscoios_xr
6.6.4
ciscoios_xr
6.6.11
ciscoios_xr
6.6.12
ciscoios_xr
6.6.25
ciscoios_xr
6.7.1
ciscoios_xr
6.7.2
ciscoios_xr
6.7.3
ciscoios_xr
6.7.4
ciscoios_xr
6.7.35
ciscoios_xr
6.8.1
ciscoios_xr
6.8.2
ciscoios_xr
6.9.1
ciscoios_xr
6.9.2
ciscoios_xr
7.0.0
ciscoios_xr
7.0.1
ciscoios_xr
7.0.2
ciscoios_xr
7.0.11
ciscoios_xr
7.0.12
ciscoios_xr
7.0.14
ciscoios_xr
7.0.90
ciscoios_xr
7.1.1
ciscoios_xr
7.1.2
ciscoios_xr
7.1.3
ciscoios_xr
7.1.15
ciscoios_xr
7.1.25
ciscoios_xr
7.2.0
ciscoios_xr
7.2.1
ciscoios_xr
7.2.2
ciscoios_xr
7.2.12
ciscoios_xr
7.3.1
ciscoios_xr
7.3.2
ciscoios_xr
7.3.3
ciscoios_xr
7.3.4
ciscoios_xr
7.3.5
ciscoios_xr
7.3.6
ciscoios_xr
7.3.15
ciscoios_xr
7.3.16
ciscoios_xr
7.3.27
ciscoios_xr
7.4.1
ciscoios_xr
7.4.2
ciscoios_xr
7.4.15
ciscoios_xr
7.4.16
ciscoios_xr
7.5.1
ciscoios_xr
7.5.2
ciscoios_xr
7.5.3
ciscoios_xr
7.5.4
ciscoios_xr
7.5.5
ciscoios_xr
7.5.12
ciscoios_xr
7.5.52
ciscoios_xr
7.6.1
ciscoios_xr
7.6.2
ciscoios_xr
7.6.3
ciscoios_xr
7.6.15
ciscoios_xr
7.7.1
ciscoios_xr
7.7.2
ciscoios_xr
7.7.21
ciscoios_xr
7.8.1
ciscoios_xr
7.8.2
ciscoios_xr
7.8.12
ciscoios_xr
7.8.22
ciscoios_xr
7.9.1
ciscoios_xr
7.9.2
ciscoios_xr
7.9.21
ciscoios_xr
7.10.1
ciscoios_xr
7.10.2
ciscoios_xr
7.11.1
ciscoios_xr
7.11.2
ciscoios_xr
24.1.1
ciscoios_xr
24.1.2
ciscoios_xr
24.2.1
ciscoios_xr
24.2.11
cisconetwork_services_orchestrator
4.4.1
cisconetwork_services_orchestrator
4.5.1
cisconetwork_services_orchestrator
4.7.1
cisconetwork_services_orchestrator
4.7.3
cisconetwork_services_orchestrator
5.1.1.1
cisconetwork_services_orchestrator
5.1.1.3
cisconetwork_services_orchestrator
5.1.2
cisconetwork_services_orchestrator
5.1.4.3
cisconetwork_services_orchestrator
5.2.0.3
cisconetwork_services_orchestrator
5.2.0.4
cisconetwork_services_orchestrator
5.2.1
cisconetwork_services_orchestrator
5.2.1.1
cisconetwork_services_orchestrator
5.2.3.2
cisconetwork_services_orchestrator
5.3.1
cisconetwork_services_orchestrator
5.3.4.3
cisconetwork_services_orchestrator
5.4
cisconetwork_services_orchestrator
5.4.0.1
cisconetwork_services_orchestrator
5.4.0.2
cisconetwork_services_orchestrator
5.4.1
cisconetwork_services_orchestrator
5.4.1.1
cisconetwork_services_orchestrator
5.4.2
cisconetwork_services_orchestrator
5.4.2.1
cisconetwork_services_orchestrator
5.4.2.2
cisconetwork_services_orchestrator
5.4.3
cisconetwork_services_orchestrator
5.4.3.1
cisconetwork_services_orchestrator
5.4.3.2
cisconetwork_services_orchestrator
5.4.3.3
cisconetwork_services_orchestrator
5.4.3.4
cisconetwork_services_orchestrator
5.4.4
cisconetwork_services_orchestrator
5.4.4.1
cisconetwork_services_orchestrator
5.4.4.2
cisconetwork_services_orchestrator
5.4.4.3
cisconetwork_services_orchestrator
5.4.5
cisconetwork_services_orchestrator
5.4.5.1
cisconetwork_services_orchestrator
5.4.5.2
cisconetwork_services_orchestrator
5.4.6
cisconetwork_services_orchestrator
5.4.7
cisconetwork_services_orchestrator
5.4.7.1
cisconetwork_services_orchestrator
5.5
cisconetwork_services_orchestrator
5.5.1
cisconetwork_services_orchestrator
5.5.2
cisconetwork_services_orchestrator
5.5.2.1
cisconetwork_services_orchestrator
5.5.2.2
cisconetwork_services_orchestrator
5.5.2.3
cisconetwork_services_orchestrator
5.5.2.4
cisconetwork_services_orchestrator
5.5.2.5
cisconetwork_services_orchestrator
5.5.2.6
cisconetwork_services_orchestrator
5.5.2.7
cisconetwork_services_orchestrator
5.5.2.8
cisconetwork_services_orchestrator
5.5.2.9
cisconetwork_services_orchestrator
5.5.2.10
cisconetwork_services_orchestrator
5.5.2.11
cisconetwork_services_orchestrator
5.5.2.12
cisconetwork_services_orchestrator
5.5.3
cisconetwork_services_orchestrator
5.5.3.1
cisconetwork_services_orchestrator
5.5.4
cisconetwork_services_orchestrator
5.5.4.1
cisconetwork_services_orchestrator
5.5.5
cisconetwork_services_orchestrator
5.5.6
cisconetwork_services_orchestrator
5.5.6.1
cisconetwork_services_orchestrator
5.5.7
cisconetwork_services_orchestrator
5.5.8
cisconetwork_services_orchestrator
5.5.9
cisconetwork_services_orchestrator
5.5.10
cisconetwork_services_orchestrator
5.6
cisconetwork_services_orchestrator
5.6.1
cisconetwork_services_orchestrator
5.6.2
cisconetwork_services_orchestrator
5.6.3
cisconetwork_services_orchestrator
5.6.3.1
cisconetwork_services_orchestrator
5.6.4
cisconetwork_services_orchestrator
5.6.5
cisconetwork_services_orchestrator
5.6.6
cisconetwork_services_orchestrator
5.6.6.1
cisconetwork_services_orchestrator
5.6.7
cisconetwork_services_orchestrator
5.6.7.1
cisconetwork_services_orchestrator
5.6.7.2
cisconetwork_services_orchestrator
5.6.8
cisconetwork_services_orchestrator
5.6.8.1
cisconetwork_services_orchestrator
5.6.9
cisconetwork_services_orchestrator
5.6.10
cisconetwork_services_orchestrator
5.6.11
cisconetwork_services_orchestrator
5.6.12
cisconetwork_services_orchestrator
5.6.13
cisconetwork_services_orchestrator
5.6.14
cisconetwork_services_orchestrator
5.6.14.1
cisconetwork_services_orchestrator
5.7
cisconetwork_services_orchestrator
5.7.1
cisconetwork_services_orchestrator
5.7.1.1
cisconetwork_services_orchestrator
5.7.2
cisconetwork_services_orchestrator
5.7.2.1
cisconetwork_services_orchestrator
5.7.3
cisconetwork_services_orchestrator
5.7.4
cisconetwork_services_orchestrator
5.7.5
cisconetwork_services_orchestrator
5.7.5.1
cisconetwork_services_orchestrator
5.7.6
cisconetwork_services_orchestrator
5.7.6.1
cisconetwork_services_orchestrator
5.7.6.2
cisconetwork_services_orchestrator
5.7.6.3
cisconetwork_services_orchestrator
5.7.7
cisconetwork_services_orchestrator
5.7.8
cisconetwork_services_orchestrator
5.7.8.1
cisconetwork_services_orchestrator
5.7.9
cisconetwork_services_orchestrator
5.7.9.1
cisconetwork_services_orchestrator
5.7.10
cisconetwork_services_orchestrator
5.7.10.1
cisconetwork_services_orchestrator
5.7.10.2
cisconetwork_services_orchestrator
5.7.11
cisconetwork_services_orchestrator
5.7.12
cisconetwork_services_orchestrator
5.7.13
cisconetwork_services_orchestrator
5.7.14
cisconetwork_services_orchestrator
5.7.15
cisconetwork_services_orchestrator
5.7.15.1
cisconetwork_services_orchestrator
5.7.17
cisconetwork_services_orchestrator
5.8
cisconetwork_services_orchestrator
5.8.1
cisconetwork_services_orchestrator
5.8.2
cisconetwork_services_orchestrator
5.8.2.1
cisconetwork_services_orchestrator
5.8.3
cisconetwork_services_orchestrator
5.8.4
cisconetwork_services_orchestrator
5.8.5
cisconetwork_services_orchestrator
5.8.6
cisconetwork_services_orchestrator
5.8.7
cisconetwork_services_orchestrator
5.8.8
cisconetwork_services_orchestrator
5.8.9
cisconetwork_services_orchestrator
5.8.10
cisconetwork_services_orchestrator
5.8.11
cisconetwork_services_orchestrator
5.8.12
cisconetwork_services_orchestrator
5.8.13
cisconetwork_services_orchestrator
6.0
cisconetwork_services_orchestrator
6.0.1
cisconetwork_services_orchestrator
6.0.1.1
cisconetwork_services_orchestrator
6.0.2
cisconetwork_services_orchestrator
6.0.3
cisconetwork_services_orchestrator
6.0.4
cisconetwork_services_orchestrator
6.0.5
cisconetwork_services_orchestrator
6.0.6
cisconetwork_services_orchestrator
6.0.7
cisconetwork_services_orchestrator
6.0.8
cisconetwork_services_orchestrator
6.0.9
cisconetwork_services_orchestrator
6.0.10
cisconetwork_services_orchestrator
6.0.11
cisconetwork_services_orchestrator
6.0.12
cisconetwork_services_orchestrator
6.1
cisconetwork_services_orchestrator
6.1.1
cisconetwork_services_orchestrator
6.1.2
cisconetwork_services_orchestrator
6.1.2.1
cisconetwork_services_orchestrator
6.1.3
cisconetwork_services_orchestrator
6.1.3.1
cisconetwork_services_orchestrator
6.1.3.2
cisconetwork_services_orchestrator
6.1.4
cisconetwork_services_orchestrator
6.1.5
cisconetwork_services_orchestrator
6.1.6
cisconetwork_services_orchestrator
6.1.6.1
cisconetwork_services_orchestrator
6.1.7
cisconetwork_services_orchestrator
6.1.7.1
cisconetwork_services_orchestrator
6.1.8
cisconetwork_services_orchestrator
6.1.10
cisconetwork_services_orchestrator
6.1.11
cisconetwork_services_orchestrator
6.1.11.1
cisconetwork_services_orchestrator
6.1.11.2
cisconetwork_services_orchestrator
6.1.12
cisconetwork_services_orchestrator
6.2
cisconetwork_services_orchestrator
6.2.2
ciscosmall_business_rv_series_router_firmware
1.0.00.29
ciscosmall_business_rv_series_router_firmware
1.0.00.33
ciscosmall_business_rv_series_router_firmware
1.0.01.16
ciscosmall_business_rv_series_router_firmware
1.0.01.17
ciscosmall_business_rv_series_router_firmware
1.0.01.18
ciscosmall_business_rv_series_router_firmware
1.0.01.20
ciscosmall_business_rv_series_router_firmware
1.0.02.16
ciscosmall_business_rv_series_router_firmware
1.0.03.15
ciscosmall_business_rv_series_router_firmware
1.0.03.16
ciscosmall_business_rv_series_router_firmware
1.0.03.17
ciscosmall_business_rv_series_router_firmware
1.0.03.18
ciscosmall_business_rv_series_router_firmware
1.0.03.19
ciscosmall_business_rv_series_router_firmware
1.0.03.20
ciscosmall_business_rv_series_router_firmware
1.0.03.21
ciscosmall_business_rv_series_router_firmware
1.0.03.22
ciscosmall_business_rv_series_router_firmware
1.0.03.24
ciscosmall_business_rv_series_router_firmware
1.0.03.26
ciscosmall_business_rv_series_router_firmware
1.0.03.27
ciscosmall_business_rv_series_router_firmware
1.0.03.28
ciscosmall_business_rv_series_router_firmware
1.0.03.29
𝑥
= Vulnerable software versions