CVE-2023-20044

A vulnerability in Cisco CX Cloud Agent of could allow an authenticated, local attacker to elevate their privileges. This vulnerability is due to insecure file permissions. An attacker could exploit this vulnerability by persuading support to update settings which call the insecure script. A successful exploit could allow the attacker to take complete control of the affected device.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cisco:cx_cloud_agent:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:40

Type Values Removed Values Added
References () https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cxagent-gOq9QjqZ - Vendor Advisory () https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cxagent-gOq9QjqZ - Vendor Advisory
CVSS v2 : unknown
v3 : 7.3
v2 : unknown
v3 : 6.7
Summary
  • (es) Una vulnerabilidad en Cisco CX Cloud Agent podría permitir que un atacante local autenticado eleve sus privilegios. Esta vulnerabilidad se debe a permisos de archivos inseguros. Un atacante podría aprovechar esta vulnerabilidad convenciendo al soporte para que actualice la configuración que llama al script inseguro. Un exploit exitoso podría permitir al atacante tomar el control total del dispositivo afectado.

25 Jan 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-01-20 07:15

Updated : 2024-11-21 07:40


NVD link : CVE-2023-20044

Mitre link : CVE-2023-20044

CVE.ORG link : CVE-2023-20044


JSON object : View

Products Affected

cisco

  • cx_cloud_agent
CWE
CWE-708

Incorrect Ownership Assignment

NVD-CWE-noinfo