← Back

CVE-2023-20046

nvd nist
Published: May 9, 2023Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

A vulnerability in the key-based SSH authentication feature of Cisco StarOS Software could allow an authenticated, remote attacker to elevate privileges on an affected device. This vulnerability is due to insufficient validation of user-supplied credentials. An attacker could exploit this vulnerability by sending a valid low-privileged SSH key to an affected device from a host that has an IP address that is configured as the source for a high-privileged user account. A successful exploit could allow the attacker to log in to the affected device through SSH as a high-privileged user. There are workarounds that address this vulnerability.

Affected (10)

Products: Cisco: Staros
1 product
Staros
Configuration A
10 vulnerable · 5 platform
Vulnerable SoftwareAffected Versions
Cisco
Before 21.22.14
From 21.23.0 to 21.23.31
From 21.25.0 to 21.25.15
From 21.26.0 to 21.26.17
From 21.27.0 to 21.27.6
From 21.28.0 to 21.28.3
Version 21.23.n
Version 21.24
Version 21.27.m
Version 21.28.m
Running on/withPlatform Versions
Cisco
Asr 5000
All versions
Cisco
Asr 5500
All versions
Cisco
Asr 5700
All versions
Cisco
Vpc Di
All versions
Cisco
Vpc Si
All versions

Timeline

No history available yet.