Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-20039


A vulnerability in Cisco IND could allow an authenticated, local attacker to read application data. This vulnerability is due to insufficient default file permissions that are applied to the application data directory. An attacker could exploit this vulnerability by accessing files in the application data directory. A successful exploit could allow the attacker to view sensitive information. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. 


Published

2024-11-15T16:15:25.157

Last Modified

2025-08-11T17:33:59.200

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-552

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application cisco industrial_network_director < 1.11.3 Yes

References