Remote Authentication Bypass Vulnerability in Cisco Emergency Responder
CVE-2023-20101
9.8CRITICAL
What is CVE-2023-20101?
A security vulnerability exists in Cisco Emergency Responder that permits an unauthorized, remote attacker to gain access to the system by exploiting default, unchangeable root account credentials. These static credentials, which are meant only for development use, expose affected systems to potential illegitimate access. An attacker leveraging this flaw could execute arbitrary commands as the root user, thereby compromising the integrity and confidentiality of the network. Organizations utilizing Cisco Emergency Responder should take immediate steps to assess their risk and apply necessary mitigations.
Affected Version(s)
Cisco Emergency Responder 12.5(1)SU4