Local Access Vulnerability in Cisco Industrial Network Director
CVE-2023-20038

8.8HIGH

Key Information:

Vendor
Cisco
Vendor
CVE Published:
20 January 2023

Badges

👾 Exploit Exists

Summary

A vulnerability exists in the monitoring application of Cisco Industrial Network Director. This issue arises from a static secret key, which is used to encrypt both local data and credentials for accessing remote systems. An authenticated, local attacker could exploit this vulnerability by gaining access to the server where the application is installed. If successfully exploited, the attacker could decrypt the stored information, gaining unauthorized access to remote systems monitored by the application, thus jeopardizing system security and integrity.

Affected Version(s)

Cisco Industrial Network Director 1.5.0

Cisco Industrial Network Director 1.5.1

Cisco Industrial Network Director 1.4.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.