← Back

CVE-2023-20235

nvd nist
Published: Oct 4, 2023Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

A vulnerability in the on-device application development workflow feature for the Cisco IOx application hosting infrastructure in Cisco IOS XE Software could allow an authenticated, remote attacker to access the underlying operating system as the root user. This vulnerability exists because Docker containers with the privileged runtime option are not blocked when they are in application development mode. An attacker could exploit this vulnerability by using the Docker CLI to access an affected device. The application development workflow is meant to be used only on development systems and not in production systems.

Affected (1)

Products: Cisco: Ios Xe
1 product
Ios Xe
Configuration A
1 vulnerable · 19 platform
Vulnerable SoftwareAffected Versions
Before 17.3.1
Running on/withPlatform Versions
Cisco
Catalyst Ie3200 Rugged Switch
All versions
Cisco
Catalyst Ie3300 Rugged Switch
All versions
Cisco
Catalyst Ie3400 Rugged Switch
All versions
Cisco
Catalyst Ir1101
All versions
Cisco
Catalyst Ir1821 K9
All versions
Cisco
Catalyst Ir1831 K9
All versions
Cisco
Catalyst Ir1833 K9
All versions
Cisco
Catalyst Ir1835 K9
All versions
Cisco
Catalyst Ir8140h K9
All versions
Cisco
Catalyst Ir8140h P K9
All versions
Cisco
Catalyst Ir8340 K9
All versions
Cisco
Ess 3300 24t Con A
All versions
Cisco
Ess 3300 24t Con E
All versions
Cisco
Ess 3300 24t Ncp A
All versions
Cisco
Ess 3300 24t Ncp E
All versions
Cisco
Ess 3300 Con A
All versions
Cisco
Ess 3300 Con E
All versions
Cisco
Ess 3300 Ncp A
All versions
Cisco
Ess 3300 Ncp E
All versions

Timeline

No history available yet.