Unauthenticated Attacker Could Read and Modify Data in Cisco Unified Intelligence Center Live Data Server
CVE-2024-20325
7.1HIGH
What is CVE-2024-20325?
A security flaw in the Live Data server of Cisco Unified Intelligence Center presents an opportunity for local attackers to gain unauthorized access to critical data. This vulnerability arises from lapses in access control related to cluster configuration CLI requests. Attackers can exploit this weakness by issuing specific CLI requests to the restricted directories of an affected device. If successful, they can not only read sensitive information but also modify internal service data, potentially compromising the integrity of the system.
Affected Version(s)
Cisco Unified Intelligence Center 11.0(1)
Cisco Unified Intelligence Center 11.0(2)
Cisco Unified Intelligence Center 11.0(3)