OS Command Injection in Cisco Email Security Appliance - CVE-2023-20075

 

OS Command Injection in Cisco Email Security Appliance - CVE-2023-20075

Published: February 15, 2023


Vulnerability identifier: #VU72310
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-20075
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to improper input validation in the CLI. A local user with Operator-level privileges or higher can inject operating system commands into a legitimate command, escape the restricted command prompt and execute arbitrary commands on the underlying operating system as the CLI process user.


Affected software

Cisco Email Security Appliance

How to mitigate CVE-2023-20075

Install updates from vendor's website.

Cisco Email Security Appliance - addressed in versions 12.5.4-041, 13.0.5-007, 13.5.4-038, 14.2.1-020, 14.3.0-032

External References

Related Security Bulletins