Unauthenticated Attacker Could Read and Modify Data in Cisco Unified Intelligence Center Live Data Server
CVE-2024-20325

7.1HIGH

Key Information:

Vendor

Cisco

Vendor
CVE Published:
21 February 2024

Badges

👾 Exploit Exists

What is CVE-2024-20325?

A security flaw in the Live Data server of Cisco Unified Intelligence Center presents an opportunity for local attackers to gain unauthorized access to critical data. This vulnerability arises from lapses in access control related to cluster configuration CLI requests. Attackers can exploit this weakness by issuing specific CLI requests to the restricted directories of an affected device. If successful, they can not only read sensitive information but also modify internal service data, potentially compromising the integrity of the system.

Affected Version(s)

Cisco Unified Intelligence Center 11.0(1)

Cisco Unified Intelligence Center 11.0(2)

Cisco Unified Intelligence Center 11.0(3)

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-20325 : Unauthenticated Attacker Could Read and Modify Data in Cisco Unified Intelligence Center Live Data Server