vulnerability
Cisco IOS-XR: CVE-2024-20489: Cisco Routed Passive Optical Network Controller Vulnerabilities
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 6 | (AV:L/AC:L/Au:S/C:C/I:C/A:N) | Sep 11, 2024 | Sep 12, 2024 | Feb 4, 2026 |
Severity
6
CVSS
(AV:L/AC:L/Au:S/C:C/I:C/A:N)
Published
Sep 11, 2024
Added
Sep 12, 2024
Modified
Feb 4, 2026
Description
A vulnerability in the storage method of the PON Controller configuration file could allow an authenticated, local attacker with low privileges to obtain the MongoDB credentials.
This vulnerability is due to improper storage of the unencrypted database credentials on the device that is running Cisco IOS XR Software. An attacker could exploit this vulnerability by accessing the configuration files on an affected system. A successful exploit could allow the attacker to view MongoDB credentials.
Solution
update-xros
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.