CVE-2023-20035 is a high-severity vulnerability in the CLI of Cisco IOS XE SD-WAN Software that allows an authenticated, local attacker to execute arbitrary commands with root-level privileges due to insufficient input validation. This vulnerability has a CVSS score of 7.8 (High) and can lead to complete system control for an attacker with limited user privileges. While there is no known public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, indicating awareness. It is not currently listed on the CISA KEV catalog, suggesting it is not being actively exploited in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe_sd-wan:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.