Privilege Escalation Vulnerability in Cisco AppDynamics PHP Agent
CVE-2023-20274
7.8HIGH
What is CVE-2023-20274?
A vulnerability found in the installer script of the Cisco AppDynamics PHP Agent could potentially allow an authenticated, local attacker to gain higher privileges on the affected system. The issue arises from inadequate permissions set by the PHP Agent installer, permitting the modification of objects within the installation directory. An attacker capitalizing on this vulnerability could execute those modified objects with elevated privileges, enabling them to escalate to root access on the device.
Affected Version(s)
Cisco AppDynamics 21.2.7
Cisco AppDynamics 21.2.8
Cisco AppDynamics 21.4.0