QID 317303
Date Published: 2023-03-27
QID 317303: Cisco Internetwork Operating System (IOS) XR Software Bootloader Unauthenticated Information Disclosure Vulnerability (cisco-sa-iosxr-load-infodisc-9rdOr5Fq)
A vulnerability in the GRand Unified Bootloader (GRUB) for Cisco IOS XR Software could allow an unauthenticated attacker with physical access to the device to view sensitive files on the console using the GRUB bootloader command line.
Affected Products
QID Detection Logic (Authenticated):
The check matches Cisco IOS XR version retrieved via Unix Auth using "show version" command.
A successful exploit could allow the attacker to view sensitive files that could be used to conduct additional attacks against the device.
Solution
Customers are advised to refer to cisco-sa-iosxr-load-infodisc-9rdOr5Fq for more information.
Vendor References
- cisco-sa-iosxr-load-infodisc-9rdOr5Fq -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-load-infodisc-9rdOr5Fq
CVEs related to QID 317303
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-iosxr-load-infodisc-9rdOr5Fq |
|