CVE-2023-20043

A vulnerability in Cisco CX Cloud Agent of could allow an authenticated, local attacker to elevate their privileges. This vulnerability is due to insecure file permissions. An attacker could exploit this vulnerability by calling the script with sudo. A successful exploit could allow the attacker to take complete control of the affected device.

Data: Cisco advisories · Cisco CSAF · NVD CVEs · NVD CPEs · CISA KEV · EPSS

SeverityMEDIUM
CVSS6.7
EPSS0.05% EPSS low
CWECWE-708
KEV
Published
Modified

Products with public affected evidence

Product Advisory Affected evidence
Cisco CX Cloud Agent cisco-sa-cxagent-gOq9QjqZ structured affected CSAF product_status