CVE-2023-20029
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
A vulnerability in the Meraki onboarding feature of Cisco IOS XE Software could allow an authenticated, local attacker to gain root level privileges on an affected device. This vulnerability is due to insufficient memory protection in the Meraki onboarding feature of an affected device. An attacker could exploit this vulnerability by modifying the Meraki registration parameters. A successful exploit could allow the attacker to elevate privileges to root.
Affected (2)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 17.7.1 |
| Running on/with | Platform Versions |
|---|---|
Cisco Catalyst 9200 | All versions |
Cisco Catalyst 9200cx | All versions |
Cisco Catalyst 9200l | All versions |
Cisco Catalyst 9300 | All versions |
Cisco Catalyst 9300 24p A | All versions |
Cisco Catalyst 9300 24p E | All versions |
Cisco Catalyst 9300 24s A | All versions |
Cisco Catalyst 9300 24s E | All versions |
Cisco Catalyst 9300 24t A | All versions |
Cisco Catalyst 9300 24t E | All versions |
Cisco Catalyst 9300 24u A | All versions |
Cisco Catalyst 9300 24u E | All versions |
Cisco Catalyst 9300 24ux A | All versions |
Cisco Catalyst 9300 24ux E | All versions |
Cisco Catalyst 9300 48p A | All versions |
Cisco Catalyst 9300 48p E | All versions |
Cisco Catalyst 9300 48s A | All versions |
Cisco Catalyst 9300 48s E | All versions |
Cisco Catalyst 9300 48t A | All versions |
Cisco Catalyst 9300 48t E | All versions |
Cisco Catalyst 9300 48u A | All versions |
Cisco Catalyst 9300 48u E | All versions |
Cisco Catalyst 9300 48un A | All versions |
Cisco Catalyst 9300 48un E | All versions |
Cisco Catalyst 9300 48uxm A | All versions |
Cisco Catalyst 9300 48uxm E | All versions |
Cisco Catalyst 9300l | All versions |
Cisco Catalyst 9300l 24p 4g A | All versions |
Cisco Catalyst 9300l 24p 4g E | All versions |
Cisco Catalyst 9300l 24p 4x A | All versions |
Cisco Catalyst 9300l 24p 4x E | All versions |
Cisco Catalyst 9300l 24t 4g A | All versions |
Cisco Catalyst 9300l 24t 4g E | All versions |
Cisco Catalyst 9300l 24t 4x A | All versions |
Cisco Catalyst 9300l 24t 4x E | All versions |
Cisco Catalyst 9300l 48p 4g A | All versions |
Cisco Catalyst 9300l 48p 4g E | All versions |
Cisco Catalyst 9300l 48p 4x A | All versions |
Cisco Catalyst 9300l 48p 4x E | All versions |
Cisco Catalyst 9300l 48t 4g A | All versions |
Cisco Catalyst 9300l 48t 4g E | All versions |
Cisco Catalyst 9300l 48t 4x A | All versions |
Cisco Catalyst 9300l 48t 4x E | All versions |
Cisco Catalyst 9300l Stack | All versions |
Cisco Catalyst 9300lm | All versions |
Cisco Catalyst 9300x | All versions |
References (2)
Source: psirt@cisco.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.