cbcvebase.
CVE-2023-20101
published 2023-10-04

CVE-2023-20101: A vulnerability in Cisco Emergency Responder could allow an unauthenticated, remote attacker to log in to an affected device using the root account, which has…

PriorityP273critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.45%
82.6th percentile
A vulnerability in Cisco Emergency Responder could allow an unauthenticated, remote attacker to log in to an affected device using the root account, which has default, static credentials that cannot be changed or deleted. This vulnerability is due to the presence of static user credentials for the root account that are typically reserved for use during development. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and execute arbitrary commands as the root user.

Affected

3 ranges
VendorProductVersion rangeFixed in
ciscocisco_emergency_responder
ciscoemergency_responder
ciscoemergency_responder_static_credentials

Detection & IOCsextracted from sources · hover to see the quote

filenameciscocm.CSCwh34565_PRIVILEGED_ACCESS_DISABLE.k4.cop.sha512
  • Target account for exploitation is the 'root' account on Cisco Emergency Responder — monitor for root-level SSH/console logins on CER devices, especially from unauthenticated or unexpected remote sources.
  • Only Cisco Emergency Responder version 12.5(1)SU4 is vulnerable; scope detection and patching efforts to that specific version.
  • Track Cisco Bug ID CSCwh34565 for patch verification; presence of the remediation COP file on the system confirms the fix has been applied.
  • ·The static root credentials cannot be changed or deleted on vulnerable versions — there is no workaround; patching to 12.5(1)SU5 (or applying the COP file) is the only remediation.
  • ·The hard-coded credentials are static and present specifically because they were reserved for development use — they exist by design in the affected build and cannot be removed without patching.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_cisco9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.