HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2023-20076

CVSS 7.2v3.1pub. 2023-02-12upd. 2024-11-21

A vulnerability in the Cisco IOx application hosting environment could allow an authenticated, remote attacker to execute arbitrary commands as root on the underlying host operating system. This vulnerability is due to incomplete sanitization of parameters that are passed in for activation of an application. An attacker could exploit this vulnerability by deploying and activating an application in the Cisco IOx application hosting environment with a crafted activation payload file. A successful exploit could allow the attacker to execute arbitrary commands as root on the underlying host operating system.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
  • Cisco 807 Industrial Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 807 Industrial Integrated Services Router Firmware

    OS
    Cisco
    15.9\(3\)m15.9\(3\)m115.9\(3\)m215.9\(3\)m2a15.9\(3\)m315.9\(3\)m415.9\(3\)m4a15.9\(3\)m515.9\(3\)m6a15.9\(3\)m6b< 15.9\(3\)
  • Cisco 809 Industrial Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 809 Industrial Integrated Services Router Firmware

    OS
    Cisco
    15.9\(3\)m15.9\(3\)m115.9\(3\)m215.9\(3\)m2a15.9\(3\)m315.9\(3\)m415.9\(3\)m4a15.9\(3\)m515.9\(3\)m6a15.9\(3\)m6b< 15.9\(3\)
  • Cisco 829 Industrial Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 829 Industrial Integrated Services Router Firmware

    OS
    Cisco
    15.9\(3\)m15.9\(3\)m115.9\(3\)m215.9\(3\)m2a15.9\(3\)m315.9\(3\)m415.9\(3\)m4a15.9\(3\)m515.9\(3\)m6a15.9\(3\)m6b< 15.9\(3\)
  • Cisco Cgr1000

    HW
    Cisco
    all versions
  • Cisco Cgr1000 Firmware

    OS
    Cisco
    < 1.16.0.1
  • Cisco Cgr1240

    HW
    Cisco
    all versions
  • Cisco Cgr1240 Firmware

    OS
    Cisco
    < 1.16.0.1
  • Cisco Ic3000 Industrial Compute Gateway

    HW
    Cisco
    < 1.4.2
  • Cisco IOS XE

    OS
    Cisco
    17.10.017.9.0 – 17.9.2 (excl.)< 17.6.5
  • Cisco Iox

    APP
    Cisco
    all versions
  • Cisco Ir510 Wpan

    HW
    Cisco
    all versions
  • Cisco Ir510 Wpan Firmware

    OS
    Cisco
    < 1.10.0.1
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2023-20198CRITICAL10.0⚠ KEVPL ✓same product

Cisco IOS XE Web UI — nieautoryzowane tworzenie konta z privilege 15

CVE-2018-0151CRITICAL9.8⚠ KEVPL ✓same product

Buffer overflow w QoS Cisco IOS/IOS XE — RCE i DoS przez UDP 18999

CVE-2017-3881CRITICAL9.8⚠ KEVPL ✓same product

RCE w Cisco IOS/IOS XE – podatność protokołu CMP przez Telnet

CVE-2026-20267CRITICAL9.0PL ✓same product

Nieprawidłowa kontrola dostępu w Cisco IOS XE Software (CVE-2026-20267)

CVE-2026-20272CRITICAL9.8PL ✓same product

Cisco IOS XE — improper neutralization of special elements (CWE-74)