Remote Authentication Bypass Vulnerability in Cisco Emergency Responder
CVE-2023-20101

9.8CRITICAL

Key Information:

Vendor
Cisco
Vendor
CVE Published:
4 October 2023

Badges

👾 Exploit Exists

Summary

A security vulnerability exists in Cisco Emergency Responder that permits an unauthorized, remote attacker to gain access to the system by exploiting default, unchangeable root account credentials. These static credentials, which are meant only for development use, expose affected systems to potential illegitimate access. An attacker leveraging this flaw could execute arbitrary commands as the root user, thereby compromising the integrity and confidentiality of the network. Organizations utilizing Cisco Emergency Responder should take immediate steps to assess their risk and apply necessary mitigations.

Affected Version(s)

Cisco Emergency Responder 12.5(1)SU4

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.