CVE-2023-20038Use of Hard-coded Cryptographic Key in Cisco Industrial Network Director

Severity
8.8HIGHNVD
EPSS
0.0%
top 86.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 20

Description

A vulnerability in the monitoring application of Cisco Industrial Network Director could allow an authenticated, local attacker to access a static secret key used to store both local data and credentials for accessing remote systems. This vulnerability is due to a static key value stored in the application used to encrypt application data and remote credentials. An attacker could exploit this vulnerability by gaining local access to the server Cisco Industrial Network Director is installed on. A

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HExploitability: 2.0 | Impact: 6.0

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-j9p6-6m27-5xwj: A vulnerability in the monitoring application of Cisco Industrial Network Director could allow an authenticated, local attacker to access a static sec2023-01-20
CVEList
CVE-2023-20038: A vulnerability in the monitoring application of Cisco Industrial Network Director could allow an authenticated, local attacker to access a static sec2023-01-19

📋Vendor Advisories

1
Cisco
Cisco Industrial Network Director Vulnerabilities2023-01-11
CVE-2023-20038 — Use of Hard-coded Cryptographic Key | cvebase