Loading HuntDB...

GHSA-vf65-x29h-36m5

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to obtain read/write file system access on the underlying operating system of an affected device.

This vulnerability is due to insufficient validation of user arguments that are passed to specific CLI commands. An attacker with a low-privileged account could exploit this vulnerability by using crafted commands at the prompt. A successful exploit could allow the attacker to elevate privileges to root.

Related CVEs

Key Information

GHSA ID
GHSA-vf65-x29h-36m5
Published
September 11, 2024 6:31 PM
Last Modified
September 11, 2024 6:31 PM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: August 1, 2025 6:16 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.