CVE-2023-20235
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
A vulnerability in the on-device application development workflow feature for the Cisco IOx application hosting infrastructure in Cisco IOS XE Software could allow an authenticated, remote attacker to access the underlying operating system as the root user.
This vulnerability exists because Docker containers with the privileged runtime option are not blocked when they are in application development mode. An attacker could exploit this vulnerability by using the Docker CLI to access an affected device. The application development workflow is meant to be used only on development systems and not in production systems.
Affected (1)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 17.3.1 |
| Running on/with | Platform Versions |
|---|---|
Cisco Catalyst Ie3200 Rugged Switch | All versions |
Cisco Catalyst Ie3300 Rugged Switch | All versions |
Cisco Catalyst Ie3400 Rugged Switch | All versions |
Cisco Catalyst Ir1101 | All versions |
Cisco Catalyst Ir1821 K9 | All versions |
Cisco Catalyst Ir1831 K9 | All versions |
Cisco Catalyst Ir1833 K9 | All versions |
Cisco Catalyst Ir1835 K9 | All versions |
Cisco Catalyst Ir8140h K9 | All versions |
Cisco Catalyst Ir8140h P K9 | All versions |
Cisco Catalyst Ir8340 K9 | All versions |
Cisco Ess 3300 24t Con A | All versions |
Cisco Ess 3300 24t Con E | All versions |
Cisco Ess 3300 24t Ncp A | All versions |
Cisco Ess 3300 24t Ncp E | All versions |
Cisco Ess 3300 Con A | All versions |
Cisco Ess 3300 Con E | All versions |
Cisco Ess 3300 Ncp A | All versions |
Cisco Ess 3300 Ncp E | All versions |
Related CWEs
CWE-269
Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
CWE-552
Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.
References (2)
Source: psirt@cisco.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.