CVE-2023-20122 describes multiple vulnerabilities in the restricted shell of Cisco Evolved Programmable Network Manager (EPNM), Cisco Identity Services Engine (ISE), and Cisco Prime Infrastructure. An authenticated, local attacker could exploit these flaws to escape the restricted shell and gain root privileges on the underlying operating system. With a CVSS score of 7.8 (High), the vulnerability has a low attack complexity and requires local authentication, but successful exploitation grants high confidentiality, integrity, and availability impact. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed on CISA's KEV catalog, indicating no active exploitation. Community discussion and media coverage are minimal, suggesting low current attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.2CPE matchmatch criteria | cpe:2.3:a:cisco:identity_services_engine:3.2:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.