CVE-2023-20076 is a high-severity vulnerability in the Cisco IOx application hosting environment, affecting Cisco industrial appliances. It allows an authenticated, remote attacker to execute arbitrary commands as root on the underlying host operating system due to incomplete sanitization of application activation parameters. A successful exploit, achieved by deploying an application with a crafted activation payload, grants full control over the host. While no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available and it's not on the KEV list, the vulnerability has garnered significant community discussion and media coverage, highlighting its potential impact, including the ability for malicious code to persist across reboots.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.4.2CPE matchmatch criteria | cpe:2.3:h:cisco:ic3000_industrial_compute_gateway:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:cisco:iox:-:*:*:*:*:*:*:* | ||
< 17.6.5CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:*:*:*:*:*:*:*:* | ||
>= 17.9.0, < 17.9.2CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:*:*:*:*:*:*:*:* | ||
17.10.0CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:17.10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.