CVE-2023-20009 is a privilege escalation vulnerability affecting Cisco Secure Email Gateway (ESA) and Cisco Secure Email and Web Manager (SMA). An authenticated remote or local attacker with operator-level privileges can exploit this flaw by uploading a specially crafted SNMP configuration file, leading to root access on the device. With a CVSS score of 7.2 (HIGH), this vulnerability allows for complete compromise of confidentiality, integrity, and availability. While not currently listed in CISA's KEV catalog and lacking public exploit code, it has garnered some community discussion and media attention, indicating awareness within the cybersecurity landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 12.5.3-041CPE matchmatch criteria | cpe:2.3:a:cisco:email_security_appliance:*:*:*:*:*:*:*:* | ||
>= 13.0.0, < 13.0.5-007CPE matchmatch criteria | cpe:2.3:a:cisco:email_security_appliance:*:*:*:*:*:*:*:* | ||
>= 13.5.0, < 13.5.4-038CPE matchmatch criteria | cpe:2.3:a:cisco:email_security_appliance:*:*:*:*:*:*:*:* | ||
>= 14.0.0, < 14.2.1-020CPE matchmatch criteria | cpe:2.3:a:cisco:email_security_appliance:*:*:*:*:*:*:*:* | ||
>= 14.3.0, < 14.3.0-032CPE matchmatch criteria | cpe:2.3:a:cisco:email_security_appliance:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.