Privilege Escalation Vulnerability in Cisco CX Cloud Agent
CVE-2023-20043

6.7MEDIUM

Key Information:

Vendor
Cisco
Vendor
CVE Published:
20 January 2023

Summary

A vulnerability exists in Cisco CX Cloud Agent that could enable an authenticated local attacker to elevate their privileges due to inadequate file permissions. By exploiting this flaw, an attacker can invoke the vulnerable script with elevated privileges using sudo, potentially gaining complete control over the affected device. Proper safeguards and timely updates are essential to mitigate this risk.

Affected Version(s)

Cisco CX Cloud Agent 0.9

Cisco CX Cloud Agent 0.0.1

Cisco CX Cloud Agent 0.0.2

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.