CVE-2023-20046 - CVE House
Back to Database
Status published High CVE-2023-20046

A vulnerability in the key-based SSH authentication feature of Cisco...

Vulnerability Description

A vulnerability in the key-based SSH authentication feature of Cisco StarOS Software could allow an authenticated, remote attacker to elevate privileges on an affected device. This vulnerability is due to insufficient validation of user-supplied credentials. An attacker could exploit this vulnerability by sending a valid low-privileged SSH key to an affected device from a host that has an IP address that is configured as the source for a high-privileged user account. A successful exploit could allow the attacker to log in to the affected device through SSH as a high-privileged user. There are workarounds that address this vulnerability.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-20046

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Cisco ASR 5000 Series Software, Cisco Ultra Cloud Core - User Plane Function
Vulnerable Versions:
21.11.0, 21.11.1, 21.11.2, 21.11.3, 21.11.10, 21.11.11, 21.11.12, 21.11.13, 21.11.14, 21.11.4, 21.11.5, 21.11.6, 21.11.7, 21.11.8, 21.11.9, 21.11.15, 21.11.16, 21.11.17, 21.11.18, 21.11.19, 21.11.20, 21.11.21, 21.12.0, 21.12.1, 21.12.2, 21.12.3, 21.12.4, 21.12.5, 21.12.6, 21.12.10, 21.12.11, 21.12.12, 21.12.13, 21.12.14, 21.12.16, 21.12.17, 21.12.18, 21.12.7, 21.12.8, 21.12.9, 21.12.19, 21.12.20, 21.12.21, 21.12.22, 21.12.15, 21.13.0, 21.13.1, 21.13.2, 21.13.3, 21.13.4, 21.13.10, 21.13.11, 21.13.12, 21.13.13, 21.13.14, 21.13.15, 21.13.16, 21.13.17, 21.13.18, 21.13.19, 21.13.20, 21.13.5, 21.13.6, 21.13.7, 21.13.8, 21.13.9, 21.13.21, 21.14.0, 21.14.1, 21.14.10, 21.14.11, 21.14.12, 21.14.16, 21.14.17, 21.14.19, 21.14.2, 21.14.20, 21.14.3, 21.14.4, 21.14.5, 21.14.6, 21.14.7, 21.14.8, 21.14.9, 21.14.b12, 21.14.b13, 21.14.b14, 21.14.b15, 21.14.b17, 21.14.b18, 21.14.b19, 21.14.b20, 21.14.b21, 21.14.22, 21.14.b22, 21.14.23, 21.15.0, 21.15.1, 21.15.10, 21.15.11, 21.15.12, 21.15.13, 21.15.14, 21.15.15, 21.15.16, 21.15.17, 21.15.18, 21.15.19, 21.15.2, 21.15.20, 21.15.21, 21.15.22, 21.15.24, 21.15.25, 21.15.26, 21.15.27, 21.15.28, 21.15.29, 21.15.3, 21.15.30, 21.15.32, 21.15.33, 21.15.36, 21.15.37, 21.15.39, 21.15.4, 21.15.40, 21.15.41, 21.15.5, 21.15.6, 21.15.7, 21.15.8, 21.15.43, 21.15.45, 21.15.46, 21.15.47, 21.15.48, 21.15.51, 21.15.52, 21.15.53, 21.15.54, 21.15.55, 21.15.57, 21.15.58, 21.15.59, 21.15.60, 21.16.2, 21.16.3, 21.16.4, 21.16.5, 21.16.c10, 21.16.c11, 21.16.c12, 21.16.c13, 21.16.c9, 21.16.d0, 21.16.d1, 21.16.6, 21.16.c14, 21.16.7, 21.16.c15, 21.16.8, 21.16.c16, 21.16.10, 21.16.9, 21.16.c17, 21.16.c18, 21.16.c19, 21.17.0, 21.17.1, 21.17.2, 21.17.3, 21.17.4, 21.17.5, 21.17.6, 21.17.7, 21.17.8, 21.17.10, 21.17.11, 21.17.9, 21.17.12, 21.17.13, 21.17.14, 21.17.15, 21.17.16, 21.17.17, 21.17.18, 21.17.19, 21.18.0, 21.18.1, 21.18.2, 21.18.3, 21.18.4, 21.18.5, 21.18.11, 21.18.6, 21.18.7, 21.18.8, 21.18.9, 21.18.12, 21.18.13, 21.18.14, 21.18.15, 21.18.16, 21.18.17, 21.18.18, 21.18.19, 21.18.20, 21.18.21, 21.18.22, 21.18.23, 21.18.24, 21.18.25, 21.18.26, 21.19.0, 21.19.1, 21.19.2, 21.19.3, 21.19.n2, 21.19.4, 21.19.5, 21.19.n3, 21.19.n4, 21.19.6, 21.19.7, 21.19.8, 21.19.n5, 21.19.10, 21.19.9, 21.19.n6, 21.19.n7, 21.19.n8, 21.19.11, 21.19.n10, 21.19.n11, 21.19.n12, 21.19.n13, 21.19.n14, 21.19.n15, 21.19.n16, 21.19.n9, 21.19.n17, 21.19.n18, 21.20.0, 21.20.1, 21.20.SV1, 21.20.SV3, 21.20.SV5, 21.20.2, 21.20.3, 21.20.4, 21.20.5, 21.20.6, 21.20.7, 21.20.8, 21.20.9, 21.20.k6, 21.20.10, 21.20.11, 21.20.k7, 21.20.u8, 21.20.12, 21.20.13, 21.20.14, 21.20.k8, 21.20.p9, 21.20.15, 21.20.16, 21.20.17, 21.20.18, 21.20.19, 21.20.20, 21.20.21, 21.20.22, 21.20.23, 21.20.24, 21.20.25, 21.20.26, 21.20.28, 21.20.29, 21.20.30, 21.20.c22, 21.20.31, 21.20.32, 21.20.33, 21.20.34, 21.20.35, 21.20.27, 21.20.SV2, 21.21.0, 21.21.1, 21.21.2, 21.21.3, 21.21.KS2, 21.22.0, 21.22.n2, 21.22.n3, 21.22.3, 21.22.4, 21.22.5, 21.22.uj3, 21.22.11, 21.22.6, 21.22.7, 21.22.8, 21.22.n4, 21.22.n5, 21.22.ua0, 21.22.ua2, 21.22.ua3, 21.22.ua5, 21.22.12, 21.22.13, 21.22.n10, 21.22.n11, 21.22.n12, 21.22.n6, 21.22.n7, 21.22.n8, 21.22.n9, 21.22.n13, 21.23.0, 21.23.1, 21.23.10, 21.23.11, 21.23.12, 21.23.13, 21.23.14, 21.23.15, 21.23.16, 21.23.17, 21.23.2, 21.23.3, 21.23.4, 21.23.5, 21.23.6, 21.23.7, 21.23.8, 21.23.9, 21.23.b2, 21.23.b3, 21.23.c16, 21.23.c17, 21.23.n6, 21.23.n7, 21.23.n9, 21.23.18, 21.23.19, 21.23.21, 21.23.22, 21.23.23, 21.23.24, 21.23.25, 21.23.26, 21.23.27, 21.23.29, 21.23.30, 21.23.c18, 21.23.n10, 21.23.n11, 21.23.n8, 21.23.yn14, 21.24.0, 21.24.1, 21.24.2, 21.24.3, 21.25.0, 21.25.3, 21.25.4, 21.25.5, 21.25.10, 21.25.11, 21.25.12, 21.25.13, 21.25.14, 21.25.6, 21.25.7, 21.25.8, 21.25.9, 21.26.0, 21.26.1, 21.26.10, 21.26.13, 21.26.14, 21.26.15, 21.26.3, 21.26.5, 21.26.6, 21.26.7, 21.26.17, 21.27.0, 21.27.1, 21.27.2, 21.27.3, 21.27.4, 21.27.5, 21.27.m0, 21.28.0, 21.28.1, 21.28.2, 21.28.m0, 21.28.m1, 21.28.m2, 21.28.m3

Timeline

Official Publish: May 9th, 2023
Last Modified: August 2nd, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.