This vulnerability is due to insufficient image verification. An attacker could exploit this vulnerability by manipulating the boot parameters for image verification during the iPXE boot process on an affected device. A successful exploit could allow the attacker to boot an unverified software image on the affected device.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-24415 | A vulnerability in the iPXE boot function of Cisco IOS XR software could allow an authenticated, local attacker to install an unverified software image on an affected device. This vulnerability is due to insufficient image verification. An attacker could exploit this vulnerability by manipulating the boot parameters for image verification during the iPXE boot process on an affected device. A successful exploit could allow the attacker to boot an unverified software image on the affected device. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 17 Dec 2025 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
ssvc
|
Wed, 23 Oct 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cisco ios Xr Software
|
|
| CPEs | cpe:2.3:o:cisco:ios_xr_software:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cisco ios Xr Software
|
|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2025-12-16T18:23:20.640Z
Reserved: 2022-10-27T18:47:50.370Z
Link: CVE-2023-20236
Updated: 2024-08-02T09:05:35.905Z
Status : Modified
Published: 2023-09-13T17:15:09.607
Modified: 2024-11-21T07:40:57.700
Link: CVE-2023-20236
No data.
OpenCVE Enrichment
No data.
EUVD