CVE-2023-20154 is a high-severity vulnerability in Cisco Modeling Labs that allows an unauthenticated, remote attacker to gain administrative access to the web interface. This flaw stems from improper handling of messages from external authentication servers, enabling a bypass of the authentication mechanism. A successful exploit, requiring valid external user credentials, grants the attacker full control over simulations and user data. While not actively exploited (KEV: No), its high CVSS score of 8.1 and significant community discussion (95th percentile) highlight its potential impact, prompting Cisco to release patches and workarounds.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.3, < 2.5.1CPE matchmatch criteria | cpe:2.3:a:cisco:modeling_labs:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.