CVE-2023-20046 is a high-severity privilege escalation vulnerability in the key-based SSH authentication feature of Cisco StarOS Software, affecting products like ASR 5000/5500/5700, StarOS, and VPC-DI/SI. An authenticated, remote attacker can exploit insufficient credential validation by sending a low-privileged SSH key from a specifically configured IP address, gaining high-privileged access. With a CVSS score of 8.8, this vulnerability has a low attack complexity and can lead to full compromise of confidentiality, integrity, and availability. While there are workarounds, there is currently no public exploit code, and it is not known to be actively exploited, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 21.22.14CPE matchmatch criteria | cpe:2.3:o:cisco:staros:*:*:*:*:*:*:*:* | ||
>= 21.23.0, < 21.23.31CPE matchmatch criteria | cpe:2.3:o:cisco:staros:*:*:*:*:*:*:*:* | ||
>= 21.25.0, < 21.25.15CPE matchmatch criteria | cpe:2.3:o:cisco:staros:*:*:*:*:*:*:*:* | ||
>= 21.26.0, < 21.26.17CPE matchmatch criteria | cpe:2.3:o:cisco:staros:*:*:*:*:*:*:*:* | ||
>= 21.27.0, < 21.27.6CPE matchmatch criteria | cpe:2.3:o:cisco:staros:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.