Aller au contenu

Fiche vulnérabilité

CVE-2023-20039 : faille moyenne Cisco Cisco Industrial Network Director (CVSS 5.5)

Description

A vulnerability in Cisco IND could allow an authenticated, local attacker to read application data. This vulnerability is due to insufficient default file permissions that are applied to the application data directory. An attacker could exploit this vulnerability by accessing files in the application data directory. A successful exploit could allow the attacker to view sensitive information. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. 

En bref

Sévérité
Moyenne (CVSS 5.5)
Vecteur CVSS
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Exploitation active
Non signalée par la CISA
Publication
15 nov. 2024
Dernière mise à jour
15 nov. 2024

Produits concernés

  • Cisco Cisco Industrial Network Director

Références

Rechercher une autre vulnérabilité dans la base CVE