Lucene search

K
cveCiscoCVE-2023-20038
HistoryJan 20, 2023 - 7:15 a.m.

CVE-2023-20038

2023-01-2007:15:15
CWE-798
CWE-321
cisco
web.nvd.nist.gov
59
cisco
industrial network director
vulnerability
monitoring
authenticated
local attacker
static secret key
remote systems
exploit
nvd

CVSS3

8.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

AI Score

8.3

Confidence

High

EPSS

0

Percentile

5.1%

A vulnerability in the monitoring application of Cisco Industrial Network Director could allow an authenticated, local attacker to access a static secret key used to store both local data and credentials for accessing remote systems.

This vulnerability is due to a static key value stored in the application used to encrypt application data and remote credentials. An attacker could exploit this vulnerability by gaining local access to the server Cisco Industrial Network Director is installed on. A successful exploit could allow the attacker to decrypt data allowing the attacker to access remote systems monitored by Cisco Industrial Network Director.

Affected configurations

Nvd
Node
ciscoindustrial_network_directorRange<1.6.0
VendorProductVersionCPE
ciscoindustrial_network_director*cpe:2.3:a:cisco:industrial_network_director:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "Cisco",
    "product": "Cisco Industrial Network Director",
    "versions": [
      {
        "version": "1.5.0",
        "status": "affected"
      },
      {
        "version": "1.5.1",
        "status": "affected"
      },
      {
        "version": "1.4.0",
        "status": "affected"
      },
      {
        "version": "1.0.0",
        "status": "affected"
      },
      {
        "version": "1.0.1",
        "status": "affected"
      }
    ]
  }
]

CVSS3

8.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

AI Score

8.3

Confidence

High

EPSS

0

Percentile

5.1%

Related for CVE-2023-20038