Permissions, Privileges, and Access Controls in Cisco Systems, Inc products - CVE-2023-20235

 

Permissions, Privileges, and Access Controls in Cisco Systems, Inc products - CVE-2023-20235

Published: October 6, 2023


Vulnerability identifier: #VU81670
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-20235
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to escalate privileges on the system.

The vulnerability exists due to the Docker containers with the privileged runtime option are not blocked when they are in application development mode within the Cisco IOx application. A remote administrator can gain access to the underlying operating system as the root user.


Affected software

Catalyst IE3x00 Rugged Series Switches
Catalyst IR8300 Rugged Series Routers
Embedded Services 3300 Series Switches
Catalyst IR1100 Rugged Series Routers
Catalyst IR1800 Rugged Series Routers
Catalyst IR8100 Heavy Duty Series Routers
Cisco IOS XE

How to mitigate CVE-2023-20235

Install updates from vendor's website.

Cisco IOS XE - addressed in versions 17.3.8, 17.6.6, 17.9.5, 17.13.1

External References

Related Security Bulletins