HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2023-20038

CVSS 8.8v3.1pub. 2023-01-20upd. 2024-11-21

A vulnerability in the monitoring application of Cisco Industrial Network Director could allow an authenticated, local attacker to access a static secret key used to store both local data and credentials for accessing remote systems. This vulnerability is due to a static key value stored in the application used to encrypt application data and remote credentials. An attacker could exploit this vulnerability by gaining local access to the server Cisco Industrial Network Director is installed on. A successful exploit could allow the attacker to decrypt data allowing the attacker to access remote systems monitored by Cisco Industrial Network Director.

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
  • Cisco Industrial Network Director

    APP
    Cisco
    < 1.6.0
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2023-20036CRITICAL9.9PL ✓same product

Command injection w Cisco Industrial Network Director — RCE jako SYSTEM

CVE-2019-1976CRITICAL9.8PL ✓same product

Nieautoryzowany dostęp do danych w komponencie plug-and-play Cisco IND

CVE-2019-1861HIGH7.2same product

A vulnerability in the software update feature of Cisco Industrial Network Director could allow an authenticat...

CVE-2023-20039MEDIUM5.5same product

A vulnerability in Cisco IND could allow an authenticated, local attacker to read application data. This vu...

CVE-2023-20037MEDIUM5.4same product

A vulnerability in Cisco Industrial Network Director could allow an authenticated, remote attacker to conduct ...