Improper Authorization in Cisco IOS and Cisco IOS XE - CVE-2023-20186

 

Improper Authorization in Cisco IOS and Cisco IOS XE - CVE-2023-20186

Published: September 28, 2023


Vulnerability identifier: #VU81248
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-20186
CWE-ID: CWE-285
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain unauthorized access to the device.

The vulnerability exists due to improper authorization checks within the Authentication, Authorization, and Accounting (AAA) feature. A local user with level 15 privileges can bypass command authorization and copy files to or from the file system of an affected device using the Secure Copy Protocol (SCP).


Affected software

Cisco IOS
Cisco IOS XE

How to mitigate CVE-2023-20186

Install updates from vendor's website.

Cisco IOS - addressed in versions 16.12.10, 17.9.1y, 17.9.4, 17.12.1
Cisco IOS XE - addressed in versions 16.12.10, 17.9.1y, 17.9.4, 17.12.1

External References

Related Security Bulletins