QID 317355
Date Published: 2023-09-20
QID 317355: Cisco Internetwork Operating System (IOS) XR Software iPXE Boot Signature Bypass Vulnerability (cisco-sa-iosxr-ipxe-sigbypass-pymfyqgB)
A vulnerability in the iPXE boot function of Cisco IOS XR software could allow an authenticated, local attacker to install an unverified software image on an affected device.
Affected Products
Cisco IOS XR prior to 7.10.1
QID Detection Logic (Authenticated):
The check matches Cisco IOS XR version retrieved via Unix Auth using "show version" command.
A successful exploit could allow the attacker to boot an unverified software image on the affected device.
Solution
Customers are advised to refer to cisco-sa-iosxr-ipxe-sigbypass-pymfyqgB for more information.
Vendor References
- cisco-sa-iosxr-ipxe-sigbypass-pymfyqgB -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-ipxe-sigbypass-pymfyqgB
CVEs related to QID 317355
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-iosxr-ipxe-sigbypass-pymfyqgB |
|