SB2023042025 - Privilege escalation in Cisco StarOS Software
Published: April 20, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Credentials management (CVE-ID: CVE-2023-20046)
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to insufficient validation of user-supplied credentials in the key-based SSH authentication feature. A remote user can send a valid low-privileged SSH key and log in to the affected device through SSH as a high-privileged user.
Remediation
Install update from vendor's website.