CVE-2023-20038 - CVE House
Back to Database
Status published High CVE-2023-20038

A vulnerability in the monitoring application of Cisco Industrial Network...

Vulnerability Description

A vulnerability in the monitoring application of Cisco Industrial Network Director could allow an authenticated, local attacker to access a static secret key used to store both local data and credentials for accessing remote systems. This vulnerability is due to a static key value stored in the application used to encrypt application data and remote credentials. An attacker could exploit this vulnerability by gaining local access to the server Cisco Industrial Network Director is installed on. A successful exploit could allow the attacker to decrypt data allowing the attacker to access remote systems monitored by Cisco Industrial Network Director.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-20038

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Cisco Industrial Network Director
Vulnerable Versions:
1.5.0, 1.5.1, 1.4.0, 1.0.0, 1.0.1

Timeline

Official Publish: January 19th, 2023
Last Modified: October 28th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Weaknesses (CWE)