CVE-2023-20186 is a critical vulnerability affecting Cisco IOS and IOS XE Software, specifically within the Authentication, Authorization, and Accounting (AAA) feature. It allows an authenticated, remote attacker with level 15 privileges to bypass command authorization checks when using Secure Copy Protocol (SCP). This flaw enables the attacker to read, modify, or exfiltrate files from the affected device, potentially altering its configuration. Rated with a CVSS score of 9.1 (Critical), this vulnerability has a low attack complexity and high impact on confidentiality, integrity, and availability. While it requires high privileges for exploitation, the potential for complete system compromise is significant. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, which is typical for a large percentage of vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.2\(58\)exCPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.2\(58\)ex:*:*:*:*:*:*:* | ||
12.2\(58\)eyCPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.2\(58\)ey:*:*:*:*:*:*:* | ||
12.2\(58\)ey1CPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.2\(58\)ey1:*:*:*:*:*:*:* | ||
12.2\(58\)ey2CPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.2\(58\)ey2:*:*:*:*:*:*:* | ||
12.2\(58\)ezCPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.2\(58\)ez:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.7 Bluesky, 0.4 Mastodon, and 1.7 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.