Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-20097


A vulnerability in Cisco access points (AP) software could allow an authenticated, local attacker to inject arbitrary commands and execute them with root privileges. This vulnerability is due to improper input validation of commands that are issued from a wireless controller to an AP. An attacker with Administrator access to the CLI of the controller could exploit this vulnerability by issuing a command with crafted arguments. A successful exploit could allow the attacker to gain full root access on the AP.


Published

2023-03-23T17:15:15.027

Last Modified

2024-11-21T07:40:32.780

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.6 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-77
  • Type: Primary
    CWE-77

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application cisco wireless_lan_controller_software < 8.10.183.0 Yes
Hardware cisco esw6300 - No
Application cisco aironet_access_point_software < 17.9.0.135 Yes
Hardware cisco aironet_1540 - No
Hardware cisco aironet_1542d - No
Hardware cisco aironet_1542i - No
Hardware cisco aironet_1560 - No
Hardware cisco aironet_1562d - No
Hardware cisco aironet_1562e - No
Hardware cisco aironet_1562i - No
Hardware cisco aironet_1800 - No
Hardware cisco aironet_1800i - No
Hardware cisco aironet_1810 - No
Hardware cisco aironet_1810w - No
Hardware cisco aironet_1815 - No
Hardware cisco aironet_1815i - No
Hardware cisco aironet_1815m - No
Hardware cisco aironet_1815t - No
Hardware cisco aironet_1815w - No
Hardware cisco aironet_2800 - No
Hardware cisco aironet_2800e - No
Hardware cisco aironet_2800i - No
Hardware cisco aironet_3800 - No
Hardware cisco aironet_3800e - No
Hardware cisco aironet_3800i - No
Hardware cisco aironet_3800p - No
Hardware cisco aironet_4800 - No
Hardware cisco catalyst_9100 - No
Hardware cisco catalyst_9105 - No
Hardware cisco catalyst_9105ax - No
Hardware cisco catalyst_9105axi - No
Hardware cisco catalyst_9105axw - No
Hardware cisco catalyst_9115 - No
Hardware cisco catalyst_9115_ap - No
Hardware cisco catalyst_9115ax - No
Hardware cisco catalyst_9115axe - No
Hardware cisco catalyst_9115axi - No
Hardware cisco catalyst_9117 - No
Hardware cisco catalyst_9117_ap - No
Hardware cisco catalyst_9117ax - No
Hardware cisco catalyst_9117axi - No
Hardware cisco catalyst_9120 - No
Hardware cisco catalyst_9120_ap - No
Hardware cisco catalyst_9120ax - No
Hardware cisco catalyst_9120axe - No
Hardware cisco catalyst_9120axi - No
Hardware cisco catalyst_9120axp - No
Hardware cisco catalyst_9124 - No
Hardware cisco catalyst_9124ax - No
Hardware cisco catalyst_9124axd - No
Hardware cisco catalyst_9124axi - No
Hardware cisco catalyst_9130 - No
Hardware cisco catalyst_9130_ap - No
Hardware cisco catalyst_9130ax - No
Hardware cisco catalyst_9130axe - No
Hardware cisco catalyst_9130axi - No
Hardware cisco catalyst_iw6300 - No
Hardware cisco catalyst_iw6300_ac - No
Hardware cisco catalyst_iw6300_dc - No
Hardware cisco catalyst_iw6300_dcw - No
Operating System cisco ios_xe < 16.12.8 Yes
Operating System cisco ios_xe < 17.3.6 Yes
Operating System cisco ios_xe < 17.6.5 Yes
Operating System cisco ios_xe < 17.9.2 Yes

References