vulnerability
Cisco IOS-XR: CVE-2024-20489: Cisco Routed Passive Optical Network Controller Vulnerabilities
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
6 | (AV:L/AC:L/Au:S/C:C/I:C/A:N) | Sep 11, 2024 | Sep 12, 2024 | Jun 23, 2025 |
Severity
6
CVSS
(AV:L/AC:L/Au:S/C:C/I:C/A:N)
Published
Sep 11, 2024
Added
Sep 12, 2024
Modified
Jun 23, 2025
Description
A vulnerability in the storage method of the PON Controller configuration file could allow an authenticated, local attacker with low privileges to obtain the MongoDB credentials.
This vulnerability is due to improper storage of the unencrypted database credentials on the device that is running Cisco IOS XR Software. An attacker could exploit this vulnerability by accessing the configuration files on an affected system. A successful exploit could allow the attacker to view MongoDB credentials.
Solution
update-xros

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.