QID 317303

Date Published: 2023-03-27

QID 317303: Cisco Internetwork Operating System (IOS) XR Software Bootloader Unauthenticated Information Disclosure Vulnerability (cisco-sa-iosxr-load-infodisc-9rdOr5Fq)

A vulnerability in the GRand Unified Bootloader (GRUB) for Cisco IOS XR Software could allow an unauthenticated attacker with physical access to the device to view sensitive files on the console using the GRUB bootloader command line.

Affected Products

QID Detection Logic (Authenticated):
The check matches Cisco IOS XR version retrieved via Unix Auth using "show version" command.

A successful exploit could allow the attacker to view sensitive files that could be used to conduct additional attacks against the device.

  • CVSS V3 rated as Medium - 4.6 severity.
  • CVSS V2 rated as Medium - 4.9 severity.
  • Solution

    Customers are advised to refer to cisco-sa-iosxr-load-infodisc-9rdOr5Fq for more information.

    CVEs related to QID 317303

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-iosxr-load-infodisc-9rdOr5Fq URL Logo sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-load-infodisc-9rdOr5Fq