Permissions, Privileges, and Access Controls in Cisco Systems, Inc products - CVE-2023-20266

 

Permissions, Privileges, and Access Controls in Cisco Systems, Inc products - CVE-2023-20266

Published: August 31, 2023


Vulnerability identifier: #VU80178
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-20266
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to escalate privileges on the system.

The vulnerability exists due to the affected application does not properly restrict the files that are being used for upgrades. A remote administrator can use a specially crafted upgrade file and elevate privileges to root.


Affected software

Cisco Emergency Responder
Cisco Unity Connection
Cisco Unified Communications Manager
Cisco Unified Communications Manager Session Management Edition

How to mitigate CVE-2023-20266

Install updates from vendor's website.

Cisco Emergency Responder - addressed in versions 12.5.1SU5, 12.5.1SU6, 12.5.1SU7, 12.5.1SU8b, 14SU3a
Cisco Unity Connection - addressed in versions 12.5.1SU8a, 14SU3a
Cisco Unified Communications Manager - update to 12.5.1SU8a
Cisco Unified Communications Manager Session Management Edition - update to 12.5.1SU8a

External References

Related Security Bulletins