CVE-2024-20456 is a medium-severity vulnerability affecting Cisco IOS XR Software, allowing an authenticated, high-privilege local attacker to bypass Cisco Secure Boot. This flaw, stemming from a software build error, enables an attacker with root-system privileges to load unverified software or alter system security properties by manipulating boot configuration. While the CVSS score is 6.7, its EPSS and FAUCET scores are low, indicating a lower likelihood of exploitation. There is currently no known public exploit code, nor is there any significant community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
24.2.1CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xr:24.2.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.