First published: Wed Sep 13 2023(Updated: )
A vulnerability in the iPXE boot function of Cisco IOS XR software could allow an authenticated, local attacker to install an unverified software image on an affected device.This vulnerability is due to insufficient image verification. An attacker could exploit this vulnerability by
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS XRv 9000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The cisco-sa-iosxr-ipxe-sigbypass-pymfyqgB vulnerability is classified as a high severity issue due to its potential impact on device integrity.
To fix the cisco-sa-iosxr-ipxe-sigbypass-pymfyqgB vulnerability, upgrade to the latest version of Cisco IOS XR software that contains the necessary patches.
Organizations using Cisco IOS XR software, particularly those running versions vulnerable to the iPXE boot function flaw, are affected by cisco-sa-iosxr-ipxe-sigbypass-pymfyqgB.
An authenticated, local attacker could exploit cisco-sa-iosxr-ipxe-sigbypass-pymfyqgB to install an unverified software image on an affected device.
The cisco-sa-iosxr-ipxe-sigbypass-pymfyqgB vulnerability is caused by insufficient image verification during the iPXE boot process in Cisco IOS XR software.