A vulnerability in the Unified Threat Defense (UTD) configuration CLI of Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying host operating system. To exploit this vulnerability, an attacker must have level 15 privileges on the affected device. 
 This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by submitting a crafted CLI command to an affected device. A successful exploit could allow the attacker to execute arbitrary commands as root on the underlying operating system.
                
            References
                    Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    30 Jul 2025, 14:04
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:o:cisco:ios_xe:17.10.1a:*:*:*:*:*:*:* cpe:2.3:o:cisco:ios_xe:17.10.1b:*:*:*:*:*:*:* cpe:2.3:o:cisco:ios_xe:17.11.1a:*:*:*:*:*:*:* cpe:2.3:o:cisco:ios_xe:17.12.1a:*:*:*:*:*:*:* cpe:2.3:o:cisco:ios_xe:17.11.1:*:*:*:*:*:*:* cpe:2.3:o:cisco:ios_xe:17.12.1:*:*:*:*:*:*:* cpe:2.3:o:cisco:ios_xe:17.12.1w:*:*:*:*:*:*:* cpe:2.3:o:cisco:ios_xe:17.11.99sw:*:*:*:*:*:*:* cpe:2.3:o:cisco:ios_xe:17.10.1:*:*:*:*:*:*:* | |
| References | () https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-utd-cmd-JbL8KvHT - Vendor Advisory | |
| First Time | Cisco Cisco ios Xe | 
21 Nov 2024, 08:52
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | 
 | |
| References | () https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-utd-cmd-JbL8KvHT - | 
27 Mar 2024, 17:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2024-03-27 17:15
Updated : 2025-07-30 14:04
NVD link : CVE-2024-20306
Mitre link : CVE-2024-20306
CVE.ORG link : CVE-2024-20306
JSON object : View
Products Affected
                cisco
- ios_xe
CWE
                
                    
                        
                        CWE-233
                        
            Improper Handling of Parameters
