CVE-2023-20103
05.04.2023, 19:15
A vulnerability in Cisco Secure Network Analytics could allow an authenticated, remote attacker to execute arbitrary code as a root user on an affected device. This vulnerability is due to insufficient validation of user input to the web interface. An attacker could exploit this vulnerability by uploading a crafted file to an affected device. A successful exploit could allow the attacker to execute code on the affected device. To exploit this vulnerability, an attacker would need to have valid Administrator credentials on the affected device.Enginsight
| Vendor | Product | Version |
|---|---|---|
| cisco | secure_network_analytics | 𝑥 < 7.4.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration