Local Access Vulnerability in Cisco Industrial Network Director
CVE-2023-20038
8.8HIGH
Summary
A vulnerability exists in the monitoring application of Cisco Industrial Network Director. This issue arises from a static secret key, which is used to encrypt both local data and credentials for accessing remote systems. An authenticated, local attacker could exploit this vulnerability by gaining access to the server where the application is installed. If successfully exploited, the attacker could decrypt the stored information, gaining unauthorized access to remote systems monitored by the application, thus jeopardizing system security and integrity.
Affected Version(s)
Cisco Industrial Network Director 1.5.0
Cisco Industrial Network Director 1.5.1
Cisco Industrial Network Director 1.4.0
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved