peter bassill · operator
$ cve CVE-2023-20036 JSON

CVE-2023-20036

9.9
CRITICAL · CVSS 3.1 · EPSS 13.8% (pctl 96)

Patch early

EPSS 13.8% — above the 10% action threshold.

Description

A vulnerability in the web UI of Cisco IND could allow an authenticated, remote attacker to execute arbitrary commands with administrative privileges on the underlying operating system of an affected device. This vulnerability is due to improper input validation when uploading a Device Pack. An attacker could exploit this vulnerability by altering the request that is sent when uploading a Device Pack. A successful exploit could allow the attacker to execute arbitrary commands as NT AUTHORITY\SYSTEM on the underlying operating system of an affected device. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

Scoring

CVSS9.9 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS13.78% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploitnone known
Published2024-11-15
Last modified2026-06-17

Affected (1)

VendorProduct
ciscoindustrial network director

References

→ the Explorer  ·  watch your stack  ·  NVD