PT-2022-7009 · Cisco · Cisco Ios Xe+1
Hendrik Van Belleghem
·
Published
2022-10-27
·
Updated
2024-11-02
·
CVE-2023-20186
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco IOS Software and Cisco IOS XE Software (affected versions not specified)
Description
A vulnerability in the Authentication, Authorization, and Accounting (AAA) feature could allow an authenticated, remote attacker to bypass command authorization and copy files to or from the file system of an affected device using the Secure Copy Protocol (SCP). This vulnerability is due to incorrect processing of SCP commands in AAA command authorization checks. An attacker with valid credentials and level 15 privileges could exploit this vulnerability by using SCP to connect to an affected device from an external machine. A successful exploit could allow the attacker to obtain or change the configuration of the affected device and put files on or retrieve files from the affected device.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, consider disabling the SCP protocol until a patch is available.
Restrict access to the affected device to minimize the risk of exploitation.
Avoid using the SCP protocol to connect to the affected device until the issue is resolved.
Apply the software updates released by Cisco that address this vulnerability.
Use the workarounds provided by Cisco that address this vulnerability.
Improper Authorization
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Ios
Cisco Ios Xe