HIGH✓ PATCH🇬🇧 English

CVE-2023-20076

CVSS 7.2v3.1pub. 2023-02-12upd. 2024-11-21

A vulnerability in the Cisco IOx application hosting environment could allow an authenticated, remote attacker to execute arbitrary commands as root on the underlying host operating system. This vulnerability is due to incomplete sanitization of parameters that are passed in for activation of an application. An attacker could exploit this vulnerability by deploying and activating an application in the Cisco IOx application hosting environment with a crafted activation payload file. A successful exploit could allow the attacker to execute arbitrary commands as root on the underlying host operating system.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
  • Cisco 807 Industrial Integrated Services Router

    HW
    Cisco
    wszystkie wersje
  • Cisco 807 Industrial Integrated Services Router Firmware

    OS
    Cisco
    15.9\(3\)m15.9\(3\)m115.9\(3\)m215.9\(3\)m2a15.9\(3\)m315.9\(3\)m415.9\(3\)m4a15.9\(3\)m515.9\(3\)m6a15.9\(3\)m6b< 15.9\(3\)
  • Cisco 809 Industrial Integrated Services Router

    HW
    Cisco
    wszystkie wersje
  • Cisco 809 Industrial Integrated Services Router Firmware

    OS
    Cisco
    15.9\(3\)m15.9\(3\)m115.9\(3\)m215.9\(3\)m2a15.9\(3\)m315.9\(3\)m415.9\(3\)m4a15.9\(3\)m515.9\(3\)m6a15.9\(3\)m6b< 15.9\(3\)
  • Cisco 829 Industrial Integrated Services Router

    HW
    Cisco
    wszystkie wersje
  • Cisco 829 Industrial Integrated Services Router Firmware

    OS
    Cisco
    15.9\(3\)m15.9\(3\)m115.9\(3\)m215.9\(3\)m2a15.9\(3\)m315.9\(3\)m415.9\(3\)m4a15.9\(3\)m515.9\(3\)m6a15.9\(3\)m6b< 15.9\(3\)
  • Cisco Cgr1000

    HW
    Cisco
    wszystkie wersje
  • Cisco Cgr1000 Firmware

    OS
    Cisco
    < 1.16.0.1
  • Cisco Cgr1240

    HW
    Cisco
    wszystkie wersje
  • Cisco Cgr1240 Firmware

    OS
    Cisco
    < 1.16.0.1
  • Cisco Ic3000 Industrial Compute Gateway

    HW
    Cisco
    < 1.4.2
  • Cisco IOS XE

    OS
    Cisco
    17.10.017.9.0 – 17.9.2 (bez)< 17.6.5
  • Cisco Iox

    APP
    Cisco
    wszystkie wersje
  • Cisco Ir510 Wpan

    HW
    Cisco
    wszystkie wersje
  • Cisco Ir510 Wpan Firmware

    OS
    Cisco
    < 1.10.0.1
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
Tagi
Command Injection
CWE
Referencje

Powiązane podatności

CVE-2023-20198CRITICAL10.0⚠ KEVPL ✓ten sam produkt

Cisco IOS XE Web UI — nieautoryzowane tworzenie konta z privilege 15

CVE-2018-0151CRITICAL9.8⚠ KEVPL ✓ten sam produkt

Buffer overflow w QoS Cisco IOS/IOS XE — RCE i DoS przez UDP 18999

CVE-2017-3881CRITICAL9.8⚠ KEVPL ✓ten sam produkt

RCE w Cisco IOS/IOS XE – podatność protokołu CMP przez Telnet

CVE-2026-20267CRITICAL9.0PL ✓ten sam produkt

Nieprawidłowa kontrola dostępu w Cisco IOS XE Software (CVE-2026-20267)

CVE-2026-20272CRITICAL9.8PL ✓ten sam produkt

Cisco IOS XE — improper neutralization of special elements (CWE-74)