PT-2022-7009 · Cisco · Cisco Ios Xe+1

Hendrik Van Belleghem

·

Published

2022-10-27

·

Updated

2024-11-02

·

CVE-2023-20186

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco IOS Software and Cisco IOS XE Software (affected versions not specified)
Description A vulnerability in the Authentication, Authorization, and Accounting (AAA) feature could allow an authenticated, remote attacker to bypass command authorization and copy files to or from the file system of an affected device using the Secure Copy Protocol (SCP). This vulnerability is due to incorrect processing of SCP commands in AAA command authorization checks. An attacker with valid credentials and level 15 privileges could exploit this vulnerability by using SCP to connect to an affected device from an external machine. A successful exploit could allow the attacker to obtain or change the configuration of the affected device and put files on or retrieve files from the affected device.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider disabling the SCP protocol until a patch is available. Restrict access to the affected device to minimize the risk of exploitation. Avoid using the SCP protocol to connect to the affected device until the issue is resolved. Apply the software updates released by Cisco that address this vulnerability. Use the workarounds provided by Cisco that address this vulnerability.

Improper Authorization

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-06410
CVE-2023-20186

Affected Products

Cisco Ios
Cisco Ios Xe