Local Access Vulnerability in Cisco Industrial Network Director
CVE-2023-20038
8.8HIGH
What is CVE-2023-20038?
A vulnerability exists in the monitoring application of Cisco Industrial Network Director. This issue arises from a static secret key, which is used to encrypt both local data and credentials for accessing remote systems. An authenticated, local attacker could exploit this vulnerability by gaining access to the server where the application is installed. If successfully exploited, the attacker could decrypt the stored information, gaining unauthorized access to remote systems monitored by the application, thus jeopardizing system security and integrity.
Affected Version(s)
Cisco Industrial Network Director 1.5.0
Cisco Industrial Network Director 1.5.1
Cisco Industrial Network Director 1.4.0