Permissions, Privileges, and Access Controls in Evolved Programmable Network (EPN) Manager and Cisco Prime Infrastructure - CVE-2023-20260
Published: January 11, 2024
Vulnerability identifier: #VU85291
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-20260
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improper processing of command line arguments to application scripts. A local administrator can gain the elevated privileges of the root user on the underlying operating system.
Affected software
Evolved Programmable Network (EPN) Manager
Cisco Prime Infrastructure
Cisco Prime Infrastructure
How to mitigate CVE-2023-20260
Install updates from vendor's website.
Evolved Programmable Network (EPN) Manager - update to 7.1.1
Cisco Prime Infrastructure - update to 3.10.4 Update 2
Cisco Prime Infrastructure - update to 3.10.4 Update 2