CVE-2023-20036
published 2024-11-15CVE-2023-20036: A vulnerability in the web UI of Cisco IND could allow an authenticated, remote attacker to execute arbitrary commands with administrative privileges on the…
PriorityP277critical9.9CVSS 3.1
AVNACLPRLUINSCCHIHAH
EPSS
12.72%
95.8th percentile
A vulnerability in the web UI of Cisco IND could allow an authenticated, remote attacker to execute arbitrary commands with administrative privileges on the underlying operating system of an affected device.
This vulnerability is due to improper input validation when uploading a Device Pack. An attacker could exploit this vulnerability by altering the request that is sent when uploading a Device Pack. A successful exploit could allow the attacker to execute arbitrary commands as NT AUTHORITY\SYSTEM on the underlying operating system of an affected device.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_industrial_network_director | — | — |
| cisco | cisco_industrial_network_director | — | — |
| cisco | cisco_industrial_network_director | — | — |
| cisco | cisco_industrial_network_director | — | — |
| cisco | cisco_industrial_network_director | — | — |
| cisco | cisco_industrial_network_director | — | — |
| cisco | cisco_industrial_network_director | — | — |
| cisco | cisco_industrial_network_director | — | — |
| cisco | cisco_industrial_network_director | — | — |
| cisco | cisco_industrial_network_director | — | — |
| cisco | cisco_industrial_network_director | — | — |
| cisco | cisco_industrial_network_director | — | — |
| cisco | cisco_industrial_network_director | — | — |
| cisco | cisco_industrial_network_director | — | — |
| cisco | cisco_industrial_network_director | — | — |
| cisco | cisco_industrial_network_director | — | — |
| cisco | cisco_industrial_network_director | — | — |
| cisco | cisco_industrial_network_director | — | — |
| cisco | cisco_industrial_network_director | — | — |
| cisco | cisco_industrial_network_director | — | — |
| cisco | industrial_network_director | < 1.11.3 | 1.11.3 |
| cisco | industrial_network_director | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit targets the Device Pack upload functionality in Cisco IND web UI; look for tampered/manipulated HTTP requests to the Device Pack upload endpoint from authenticated sessions ↗
- →Successful exploitation results in command execution as NT AUTHORITY\SYSTEM on the underlying OS; monitor for unexpected SYSTEM-level process spawning from the Cisco IND web service process ↗
- →Vulnerability is classified as OS command injection (CWE-78); monitor Cisco IND web UI logs for anomalous Device Pack upload requests containing shell metacharacters or unexpected parameter values ↗
- →Track Cisco bug IDs CSCwc29352 and CSCwc29354 for patch status; unpatched Cisco IND instances are vulnerable to authenticated remote command injection ↗
- ·Exploitation requires prior authentication to the Cisco IND web UI; attack surface is limited to authenticated users, but privilege escalation to SYSTEM makes it critical ↗
- ·No workarounds exist; the only mitigation is applying Cisco's released software updates ↗
CVSS provenance
nvdv3.19.9CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
vendor_cisco9.9CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Industrial Network Director Vulnerabilities
vendor_cisco·2023-04-19·CVSS 9.9
CVE-2023-20036 [CRITICAL] CWE-552 Cisco Industrial Network Director Vulnerabilities
Cisco Industrial Network Director Vulnerabilities
Multiple vulnerabilities in Cisco Industrial Network Director (IND) could allow an authenticated attacker to inject arbitrary operating system commands or access sensitive data.
For more information about these vulnerabilities, see the Details section of this advisory.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ind-CAeLFk6V
Cisco
Cisco Industrial Network Director Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2023-20036 Cisco Industrial Network Director Vulnerabilities
CVE-2023-20036: Cisco Industrial Network Director Vulnerabilities
Multiple vulnerabilities in Cisco Industrial Network Director (IND) could allow an authenticated attacker to inject arbitrary operating system commands or access sensitive data. For more information about these vulnerabilities, see the
CVSS: 3.1
CWE: CWE-552, CWE-78, CWE-552, CWE-78
Bug IDs: CSCwc29352, CSCwc29354, CSCwc29354, CSCwc29352
GHSA
GHSA-c6cm-r234-phmq: A vulnerability in the web UI of Cisco IND could allow an authenticated, remote attacker to execute arbitrary commands with administrative privileges
ghsa_unreviewed·2024-11-15
CVE-2023-20036 [CRITICAL] CWE-78 GHSA-c6cm-r234-phmq: A vulnerability in the web UI of Cisco IND could allow an authenticated, remote attacker to execute arbitrary commands with administrative privileges
A vulnerability in the web UI of Cisco IND could allow an authenticated, remote attacker to execute arbitrary commands with administrative privileges on the underlying operating system of an affected device.
This vulnerability is due to improper input validation when uploading a Device Pack. An attacker could exploit this vulnerability by altering the request that is sent when uploading a Device Pack. A successful exploit could allow the attacker to execute arbitrary commands as NT AUTHORITY\SYSTEM on the underlying operating system of an affected device.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
No detection rules found.
No public exploits indexed.
2024-11-15
Published