CVE-2023-20260: Medium severity cisco evolved programmable network manager vulnerability
A vulnerability in the application CLI of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager could allow an authenticated, local attacker to gain escalated privileges. This vulnerability is due to improper processing of command line arguments to application scripts. An attacker could exploit this vulnerability by issuing a command on the CLI with malicious options. A successful exploit could allow the attacker to gain the escalated privileges of the root user on the underlying operating system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-20260?
CVE-2023-20260 is classified as a high-severity vulnerability due to its potential to allow unauthorized privilege escalation.
How do I fix CVE-2023-20260?
To mitigate CVE-2023-20260, upgrade Cisco Prime Infrastructure to version 3.10.4-update_1 or later and Cisco Evolved Programmable Network Manager to version 7.1.1 or later.
What are the affected versions of software for CVE-2023-20260?
CVE-2023-20260 affects Cisco Prime Infrastructure versions up to 3.10.4 and Cisco Evolved Programmable Network Manager versions up to 7.1.1.
Who can exploit CVE-2023-20260?
CVE-2023-20260 can be exploited by an authenticated, local attacker with access to the command line interface.
What kind of attack does CVE-2023-20260 involve?
CVE-2023-20260 involves an attack that takes advantage of improper processing of command line arguments, potentially leading to escalated privileges.