CVE-2023-20044 is a privilege escalation vulnerability affecting Cisco CX Cloud Agent. An authenticated, local attacker can exploit insecure file permissions by persuading support to update settings that call a vulnerable script. This allows the attacker to gain complete control of the affected device. The vulnerability has a CVSS score of 7.3 (HIGH), indicating a significant impact, but currently has no known public exploits, Metasploit modules, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.2.1CPE matchmatch criteria | cpe:2.3:a:cisco:cx_cloud_agent:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.