QID 378443
Date Published: 2023-04-25
QID 378443: Cisco Industrial Network Director Static Private Key Vulnerability (cisco-sa-ind-fZyVjJtG) (CVE-2023-20038)
A vulnerability in the monitoring application of Cisco IND could allow an authenticated, local attacker to access a static private key that is used to encrypt both local data and credentials for accessing remote systems.
Affected Products
Cisco IND Release 1 and prior to 1.6.0
QID Detection Logic (authenticated):
The QID matches version of Cisco Industrial Network Director using registry "HKEY_LOCAL_MACHINE\SOFTWARE\Cisco\Cisco Industrial Network Director"
A successful exploit could allow the attacker to decrypt local data or access remote systems monitored by Cisco IND.
Solution
Customers are advised to refer to cisco-sa-ind-fZyVjJtG
Vendor References
- cisco-sa-ind-fZyVjJtG -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ind-fZyVjJtG
CVEs related to QID 378443
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-ind-fZyVjJtG |
|