MEDIUM✓ PATCH🇵🇱 Wersja polska

CVE-2023-20039

CVSS 5.5v3.1pub. 2024-11-15upd. 2025-08-11

A vulnerability in Cisco IND could allow an authenticated, local attacker to read application data. This vulnerability is due to insufficient default file permissions that are applied to the application data directory. An attacker could exploit this vulnerability by accessing files in the application data directory. A successful exploit could allow the attacker to view sensitive information. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. 

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
  • Cisco Industrial Network Director

    APP
    Cisco
    < 1.11.3
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2023-20036CRITICAL9.9PL ✓same product

Command injection w Cisco Industrial Network Director — RCE jako SYSTEM

CVE-2019-1976CRITICAL9.8PL ✓same product

Nieautoryzowany dostęp do danych w komponencie plug-and-play Cisco IND

CVE-2023-20038HIGH8.8same product

A vulnerability in the monitoring application of Cisco Industrial Network Director could allow an authenticate...

CVE-2019-1861HIGH7.2same product

A vulnerability in the software update feature of Cisco Industrial Network Director could allow an authenticat...

CVE-2023-20037MEDIUM5.4same product

A vulnerability in Cisco Industrial Network Director could allow an authenticated, remote attacker to conduct ...