A vulnerability in the Cisco IOx application hosting subsystem of Cisco IOS XE Software could allow an authenticated, local attacker to elevate privileges to root on an affected device.
This vulnerability is due to insufficient restrictions on the hosted application. An attacker could exploit this vulnerability by logging in to and then escaping the Cisco IOx application container. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with root privileges.
This vulnerability is due to insufficient restrictions on the hosted application. An attacker could exploit this vulnerability by logging in to and then escaping the Cisco IOx application container. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with root privileges.
Metrics
No CVSS v4.0
Attack Vector Local
Attack Complexity Low
Privileges Required Low
Scope Unchanged
Confidentiality Impact High
Integrity Impact High
Availability Impact High
User Interaction None
No CVSS v3.0
No CVSS v2
This CVE is not in the KEV list.
The EPSS score is 0.0006.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
| Vendors | Products |
|---|---|
|
Cisco
Subscribe
|
1000 Integrated Services Router
Subscribe
1100-4g Integrated Services Router
Subscribe
1100-4p Integrated Services Router
Subscribe
1100-6g Integrated Services Router
Subscribe
1100-8p Integrated Services Router
Subscribe
1100 Integrated Services Router
Subscribe
1101-4p Integrated Services Router
Subscribe
1101 Integrated Services Router
Subscribe
1109-2p Integrated Services Router
Subscribe
1109-4p Integrated Services Router
Subscribe
1109 Integrated Services Router
Subscribe
1111x-8p Integrated Services Router
Subscribe
1111x Integrated Services Router
Subscribe
111x Integrated Services Router
Subscribe
1120 Integrated Services Router
Subscribe
1131 Integrated Services Router
Subscribe
1160 Integrated Services Router
Subscribe
4000 Integrated Services Router
Subscribe
4221 Integrated Services Router
Subscribe
4321 Integrated Services Router
Subscribe
4331 Integrated Services Router
Subscribe
4351 Integrated Services Router
Subscribe
4431 Integrated Services Router
Subscribe
4451-x Integrated Services Router
Subscribe
4451 Integrated Services Router
Subscribe
4461 Integrated Services Router
Subscribe
8101-32fh
Subscribe
8101-32h
Subscribe
8102-64h
Subscribe
8201
Subscribe
8201-32fh
Subscribe
8202
Subscribe
8800 12-slot
Subscribe
8800 18-slot
Subscribe
8800 4-slot
Subscribe
8800 8-slot
Subscribe
8804
Subscribe
8808
Subscribe
8812
Subscribe
8818
Subscribe
8831
Subscribe
9800-40
Subscribe
9800-80
Subscribe
9800-cl
Subscribe
9800-l
Subscribe
Asr 1000
Subscribe
Asr 1000-esp100
Subscribe
Asr 1000-esp100-x
Subscribe
Asr 1000-esp200-x
Subscribe
Asr 1001
Subscribe
Asr 1001-hx
Subscribe
Asr 1001-hx R
Subscribe
Asr 1001-x
Subscribe
Asr 1001-x R
Subscribe
Asr 1002
Subscribe
Asr 1002-hx
Subscribe
Asr 1002-hx R
Subscribe
Asr 1002-x
Subscribe
Asr 1002-x R
Subscribe
Asr 1004
Subscribe
Asr 1006
Subscribe
Asr 1006-x
Subscribe
Asr 1009-x
Subscribe
Asr 1013
Subscribe
Asr 1023
Subscribe
Asr 900
Subscribe
Asr 9000
Subscribe
Asr 9000v
Subscribe
Asr 9001
Subscribe
Asr 9006
Subscribe
Asr 901-12c-f-d
Subscribe
Asr 901-12c-ft-d
Subscribe
Asr 901-4c-f-d
Subscribe
Asr 901-4c-ft-d
Subscribe
Asr 901-6cz-f-a
Subscribe
Asr 901-6cz-f-d
Subscribe
Asr 901-6cz-fs-a
Subscribe
Asr 901-6cz-fs-d
Subscribe
Asr 901-6cz-ft-a
Subscribe
Asr 901-6cz-ft-d
Subscribe
Asr 9010
Subscribe
Asr 901s-2sg-f-ah
Subscribe
Asr 901s-2sg-f-d
Subscribe
Asr 901s-3sg-f-ah
Subscribe
Asr 901s-3sg-f-d
Subscribe
Asr 901s-4sg-f-d
Subscribe
Asr 902
Subscribe
Asr 902u
Subscribe
Asr 903
Subscribe
Asr 907
Subscribe
Asr 914
Subscribe
Asr 920-10sz-pd
Subscribe
Asr 920-10sz-pd R
Subscribe
Asr 920-12cz-a
Subscribe
Asr 920-12cz-a R
Subscribe
Asr 920-12cz-d
Subscribe
Asr 920-12cz-d R
Subscribe
Asr 920-12sz-im
Subscribe
Asr 920-12sz-im R
Subscribe
Asr 920-24sz-im
Subscribe
Asr 920-24sz-im R
Subscribe
Asr 920-24sz-m
Subscribe
Asr 920-24sz-m R
Subscribe
Asr 920-24tz-m
Subscribe
Asr 920-24tz-m R
Subscribe
Asr 920-4sz-a
Subscribe
Asr 920-4sz-a R
Subscribe
Asr 920-4sz-d
Subscribe
Asr 920-4sz-d R
Subscribe
Asr 920u-12sz-im
Subscribe
Asr 9901
Subscribe
Asr 9902
Subscribe
Asr 9903
Subscribe
Asr 9904
Subscribe
Asr 9906
Subscribe
Asr 9910
Subscribe
Asr 9912
Subscribe
Asr 9920
Subscribe
Asr 9922
Subscribe
Catalyst 3850
Subscribe
Catalyst 3850-12s-e
Subscribe
Catalyst 3850-12s-s
Subscribe
Catalyst 3850-12x48u
Subscribe
Catalyst 3850-12xs-e
Subscribe
Catalyst 3850-12xs-s
Subscribe
Catalyst 3850-16xs-e
Subscribe
Catalyst 3850-16xs-s
Subscribe
Catalyst 3850-24p-e
Subscribe
Catalyst 3850-24p-l
Subscribe
Catalyst 3850-24p-s
Subscribe
Catalyst 3850-24pw-s
Subscribe
Catalyst 3850-24s-e
Subscribe
Catalyst 3850-24s-s
Subscribe
Catalyst 3850-24t-e
Subscribe
Catalyst 3850-24t-l
Subscribe
Catalyst 3850-24t-s
Subscribe
Catalyst 3850-24u
Subscribe
Catalyst 3850-24u-e
Subscribe
Catalyst 3850-24u-l
Subscribe
Catalyst 3850-24u-s
Subscribe
Catalyst 3850-24xs
Subscribe
Catalyst 3850-24xs-e
Subscribe
Catalyst 3850-24xs-s
Subscribe
Catalyst 3850-24xu
Subscribe
Catalyst 3850-24xu-e
Subscribe
Catalyst 3850-24xu-l
Subscribe
Catalyst 3850-24xu-s
Subscribe
Catalyst 3850-32xs-e
Subscribe
Catalyst 3850-32xs-s
Subscribe
Catalyst 3850-48f-e
Subscribe
Catalyst 3850-48f-l
Subscribe
Catalyst 3850-48f-s
Subscribe
Catalyst 3850-48p-e
Subscribe
Catalyst 3850-48p-l
Subscribe
Catalyst 3850-48p-s
Subscribe
Catalyst 3850-48pw-s
Subscribe
Catalyst 3850-48t-e
Subscribe
Catalyst 3850-48t-l
Subscribe
Catalyst 3850-48t-s
Subscribe
Catalyst 3850-48u
Subscribe
Catalyst 3850-48u-e
Subscribe
Catalyst 3850-48u-l
Subscribe
Catalyst 3850-48u-s
Subscribe
Catalyst 3850-48xs
Subscribe
Catalyst 3850-48xs-e
Subscribe
Catalyst 3850-48xs-f-e
Subscribe
Catalyst 3850-48xs-f-s
Subscribe
Catalyst 3850-48xs-s
Subscribe
Catalyst 3850-nm-2-40g
Subscribe
Catalyst 3850-nm-8-10g
Subscribe
Catalyst 8200
Subscribe
Catalyst 8300
Subscribe
Catalyst 8300-1n1s-4t2x
Subscribe
Catalyst 8300-1n1s-6t
Subscribe
Catalyst 8300-2n2s-4t2x
Subscribe
Catalyst 8300-2n2s-6t
Subscribe
Catalyst 8500
Subscribe
Catalyst 8500-4qc
Subscribe
Catalyst 8500l
Subscribe
Catalyst 8510csr
Subscribe
Catalyst 8510msr
Subscribe
Catalyst 8540csr
Subscribe
Catalyst 8540msr
Subscribe
Catalyst 9200
Subscribe
Catalyst 9200cx
Subscribe
Catalyst 9200l
Subscribe
Catalyst 9300
Subscribe
Catalyst 9300-24p-a
Subscribe
Catalyst 9300-24p-e
Subscribe
Catalyst 9300-24s-a
Subscribe
Catalyst 9300-24s-e
Subscribe
Catalyst 9300-24t-a
Subscribe
Catalyst 9300-24t-e
Subscribe
Catalyst 9300-24u-a
Subscribe
Catalyst 9300-24u-e
Subscribe
Catalyst 9300-24ux-a
Subscribe
Catalyst 9300-24ux-e
Subscribe
Catalyst 9300-48p-a
Subscribe
Catalyst 9300-48p-e
Subscribe
Catalyst 9300-48s-a
Subscribe
Catalyst 9300-48s-e
Subscribe
Catalyst 9300-48t-a
Subscribe
Catalyst 9300-48t-e
Subscribe
Catalyst 9300-48u-a
Subscribe
Catalyst 9300-48u-e
Subscribe
Catalyst 9300-48un-a
Subscribe
Catalyst 9300-48un-e
Subscribe
Catalyst 9300-48uxm-a
Subscribe
Catalyst 9300-48uxm-e
Subscribe
Catalyst 9300l
Subscribe
Catalyst 9300l-24p-4g-a
Subscribe
Catalyst 9300l-24p-4g-e
Subscribe
Catalyst 9300l-24p-4x-a
Subscribe
Catalyst 9300l-24p-4x-e
Subscribe
Catalyst 9300l-24t-4g-a
Subscribe
Catalyst 9300l-24t-4g-e
Subscribe
Catalyst 9300l-24t-4x-a
Subscribe
Catalyst 9300l-24t-4x-e
Subscribe
Catalyst 9300l-48p-4g-a
Subscribe
Catalyst 9300l-48p-4g-e
Subscribe
Catalyst 9300l-48p-4x-a
Subscribe
Catalyst 9300l-48p-4x-e
Subscribe
Catalyst 9300l-48t-4g-a
Subscribe
Catalyst 9300l-48t-4g-e
Subscribe
Catalyst 9300l-48t-4x-a
Subscribe
Catalyst 9300l-48t-4x-e
Subscribe
Catalyst 9300l Stack
Subscribe
Catalyst 9300lm
Subscribe
Catalyst 9300x
Subscribe
Catalyst 9400
Subscribe
Catalyst 9400 Supervisor Engine-1
Subscribe
Catalyst 9407r
Subscribe
Catalyst 9410r
Subscribe
Catalyst 9500
Subscribe
Catalyst 9500h
Subscribe
Catalyst 9600
Subscribe
Catalyst 9600 Supervisor Engine-1
Subscribe
Catalyst 9600x
Subscribe
Catalyst 9800
Subscribe
Catalyst 9800-40
Subscribe
Catalyst 9800-40 Wireless Controller
Subscribe
Catalyst 9800-80
Subscribe
Catalyst 9800-80 Wireless Controller
Subscribe
Catalyst 9800-cl
Subscribe
Catalyst 9800-l
Subscribe
Catalyst 9800-l-c
Subscribe
Catalyst 9800-l-f
Subscribe
Catalyst 9800 Embedded Wireless Controller
Subscribe
Catalyst Ie3200
Subscribe
Catalyst Ie3200 Rugged Switch
Subscribe
Catalyst Ie3300
Subscribe
Catalyst Ie3300 Rugged Switch
Subscribe
Catalyst Ie3400
Subscribe
Catalyst Ie3400 Heavy Duty Switch
Subscribe
Catalyst Ie3400 Rugged Switch
Subscribe
Catalyst Ie9300
Subscribe
Cbr-8
Subscribe
Cg418-e
Subscribe
Cg522-e
Subscribe
Esr6300
Subscribe
Ess-3300-24t-con-a
Subscribe
Ess-3300-24t-con-e
Subscribe
Ess-3300-24t-ncp-a
Subscribe
Ess-3300-24t-ncp-e
Subscribe
Ess-3300-con-a
Subscribe
Ess-3300-con-e
Subscribe
Ess-3300-ncp-a
Subscribe
Ess-3300-ncp-e
Subscribe
Ess9300-10x-e
Subscribe
Integrated Services Virtual Router
Subscribe
Ios Xe
Subscribe
|
Configuration 1 [-]
| AND |
|
No data.
No data.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-24244 | A vulnerability in the Cisco IOx application hosting subsystem of Cisco IOS XE Software could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability is due to insufficient restrictions on the hosted application. An attacker could exploit this vulnerability by logging in to and then escaping the Cisco IOx application container. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with root privileges. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-08-02T08:57:35.585Z
Reserved: 2022-10-27T00:00:00
Link: CVE-2023-20065
No data.
Status : Modified
Published: 2023-03-23T17:15:14.393
Modified: 2024-11-21T07:40:28.227
Link: CVE-2023-20065
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD