First published: Wed Apr 05 2023(Updated: )
Multiple vulnerabilities in the restricted shell of Cisco Evolved Programmable Network Manager (EPNM), Cisco Identity Services Engine (ISE), and Cisco Prime Infrastructure could allow an authenticated, local attacker to escape the restricted shell and gain root privileges on the underlying operating system. For more information about these vulnerabilities, see the Details section of this advisory.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Evolved Programmable Network Manager | <7.0.1 | |
Cisco Identity Services Engine | =3.2 | |
Cisco Prime Infrastructure | <3.10.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for these multiple vulnerabilities is CVE-2023-20121.
The severity level of CVE-2023-20121 is medium.
CVE-2023-20121 affects Cisco Evolved Programmable Network Manager (EPNM), Cisco Identity Services Engine (ISE), and Cisco Prime Infrastructure.
An authenticated, local attacker can exploit CVE-2023-20121 to escape the restricted shell and gain root privileges on the underlying operating system.
Yes, Cisco has released security updates to address these vulnerabilities. Please refer to the Cisco Security Advisory for more information.