Логотип exploitDog
bind:CVE-2023-20038
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-20038

Количество 3

Количество 3

nvd логотип

CVE-2023-20038

около 3 лет назад

A vulnerability in the monitoring application of Cisco Industrial Network Director could allow an authenticated, local attacker to access a static secret key used to store both local data and credentials for accessing remote systems. This vulnerability is due to a static key value stored in the application used to encrypt application data and remote credentials. An attacker could exploit this vulnerability by gaining local access to the server Cisco Industrial Network Director is installed on. A successful exploit could allow the attacker to decrypt data allowing the attacker to access remote systems monitored by Cisco Industrial Network Director.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-j9p6-6m27-5xwj

около 3 лет назад

A vulnerability in the monitoring application of Cisco Industrial Network Director could allow an authenticated, local attacker to access a static secret key used to store both local data and credentials for accessing remote systems. This vulnerability is due to a static key value stored in the application used to encrypt application data and remote credentials. An attacker could exploit this vulnerability by gaining local access to the server Cisco Industrial Network Director is installed on. A successful exploit could allow the attacker to decrypt data allowing the attacker to access remote systems monitored by Cisco Industrial Network Director.

CVSS3: 8.8
EPSS: Низкий
fstec логотип

BDU:2023-00350

около 3 лет назад

Уязвимость программного пакета Cisco Industrial Network Director, связанная с возможностью получения доступа к статическому секретному ключу, позволяющая нарушителю получить доступ ко всем контролируемым системам

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-20038

A vulnerability in the monitoring application of Cisco Industrial Network Director could allow an authenticated, local attacker to access a static secret key used to store both local data and credentials for accessing remote systems. This vulnerability is due to a static key value stored in the application used to encrypt application data and remote credentials. An attacker could exploit this vulnerability by gaining local access to the server Cisco Industrial Network Director is installed on. A successful exploit could allow the attacker to decrypt data allowing the attacker to access remote systems monitored by Cisco Industrial Network Director.

CVSS3: 8.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-j9p6-6m27-5xwj

A vulnerability in the monitoring application of Cisco Industrial Network Director could allow an authenticated, local attacker to access a static secret key used to store both local data and credentials for accessing remote systems. This vulnerability is due to a static key value stored in the application used to encrypt application data and remote credentials. An attacker could exploit this vulnerability by gaining local access to the server Cisco Industrial Network Director is installed on. A successful exploit could allow the attacker to decrypt data allowing the attacker to access remote systems monitored by Cisco Industrial Network Director.

CVSS3: 8.8
0%
Низкий
около 3 лет назад
fstec логотип
BDU:2023-00350

Уязвимость программного пакета Cisco Industrial Network Director, связанная с возможностью получения доступа к статическому секретному ключу, позволяющая нарушителю получить доступ ко всем контролируемым системам

CVSS3: 8.8
0%
Низкий
около 3 лет назад

Уязвимостей на страницу