CVE-2023-20043

A vulnerability in Cisco CX Cloud Agent of could allow an authenticated, local attacker to elevate their privileges. This vulnerability is due to insecure file permissions. An attacker could exploit this vulnerability by calling the script with sudo. A successful exploit could allow the attacker to take complete control of the affected device.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:cisco:cx_cloud_agent:*:*:*:*:*:*:*:*
cpe:2.3:a:cisco:cx_cloud_agent:2.2:*:*:*:*:*:*:*

History

21 Nov 2024, 07:40

Type Values Removed Values Added
References () https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cxagent-gOq9QjqZ - Vendor Advisory () https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cxagent-gOq9QjqZ - Vendor Advisory
Summary
  • (es) Una vulnerabilidad en Cisco CX Cloud Agent podría permitir que un atacante local autenticado eleve sus privilegios. Esta vulnerabilidad se debe a permisos de archivos inseguros. Un atacante podría aprovechar esta vulnerabilidad llamando al script con sudo. Un exploit exitoso podría permitir al atacante tomar el control total del dispositivo afectado.

07 Nov 2023, 04:05

Type Values Removed Values Added
Summary A vulnerability in Cisco CX Cloud Agent of could allow an authenticated, local attacker to elevate their privileges. This vulnerability is due to insecure file permissions. An attacker could exploit this vulnerability by calling the script with sudo. A successful exploit could allow the attacker to take complete control of the affected device. A vulnerability in Cisco CX Cloud Agent of could allow an authenticated, local attacker to elevate their privileges. This vulnerability is due to insecure file permissions. An attacker could exploit this vulnerability by calling the script with sudo. A successful exploit could allow the attacker to take complete control of the affected device.

Information

Published : 2023-01-20 07:15

Updated : 2024-11-21 07:40


NVD link : CVE-2023-20043

Mitre link : CVE-2023-20043

CVE.ORG link : CVE-2023-20043


JSON object : View

Products Affected

cisco

  • cx_cloud_agent
CWE
CWE-708

Incorrect Ownership Assignment

CWE-276

Incorrect Default Permissions