CVE-2023-20217
Summary
| CVE | CVE-2023-20217 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-08-16 22:15:00 UTC |
| Updated | 2024-01-25 17:15:00 UTC |
| Description | A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent, Virtual Appliance installation type, could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient input validation by the operating system CLI. An attacker could exploit this vulnerability by issuing certain commands using sudo. A successful exploit could allow the attacker to view arbitrary files as root on the underlying operating system. The attacker must have valid credentials on the affected device. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Thousandeyes Enterprise Agent | All | All | All | All |
| Application | Cisco | Thousandeyes Recorder | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco ThousandEyes Enterprise Agent Virtual Appliance Privilege Escalation Vulnerability | MISC | sec.cloudapps.cisco.com | |
| Cisco ThousandEyes Enterprise Agent Virtual Appliance Arbitrary File Read ≈ Packet Storm | MISC | packetstormsecurity.com | |
| Full Disclosure: KL-001-2023-001: Cisco ThousandEyes Enterprise Agent Virtual Appliance Arbitrary File Read via sudo dig | MISC | seclists.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.