Improper Authorization in Cisco IOS and Cisco IOS XE - CVE-2023-20186
Published: September 28, 2023
Vulnerability details
The vulnerability allows a local user to gain unauthorized access to the device.
The vulnerability exists due to improper authorization checks within the Authentication, Authorization, and Accounting (AAA) feature. A local user with level 15 privileges can bypass command authorization and copy files to or from the file system of an affected device using the Secure Copy Protocol (SCP).
Affected software
Cisco IOS XE
How to mitigate CVE-2023-20186
Cisco IOS XE - addressed in versions 16.12.10, 17.9.1y, 17.9.4, 17.12.1