CVE-2023-20260 - CVE House
Back to Database
Status published Medium CVE-2023-20260

A vulnerability in the application CLI of Cisco Prime Infrastructure...

Vulnerability Description

A vulnerability in the application CLI of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager could allow an authenticated, local attacker to gain escalated privileges. This vulnerability is due to improper processing of command line arguments to application scripts. An attacker could exploit this vulnerability by issuing a command on the CLI with malicious options. A successful exploit could allow the attacker to gain the escalated privileges of the root user on the underlying operating system.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-20260

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Cisco Prime Infrastructure, Cisco Evolved Programmable Network Manager (EPNM)
Vulnerable Versions:
2.0.0, 2.0.10, 2.0.39, 2.1.0, 2.1.1, 2.1.2, 2.1.56, 2.2.0, 2.2.1, 2.2.2, 2.2.3, 2.2.10, 2.2.8, 2.2.4, 2.2.7, 2.2.5, 2.2.9, 2.2.1 Update 01, 2.2.2 Update 03, 2.2.2 Update 04, 2.2.3 Update 02, 2.2.3 Update 03, 2.2.3 Update 04, 2.2.3 Update 05, 2.2.3 Update 06, 3.0.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4, 3.0.6, 3.0.5, 3.0.7, 3.1.0, 3.1.1, 3.1.7, 3.1.5, 3.1.2, 3.1.3, 3.1.4, 3.1.6, 3.2.2, 3.2.0-FIPS, 3.2.1, 3.3.0, 3.3.1, 3.3.0 Update 01, 3.4.0, 3.4.1, 3.4.2, 3.4.1 Update 01, 3.4.1 Update 02, 3.4.2 Update 01, 3.5.0, 3.5.1, 3.5.0 Update 01, 3.5.0 Update 02, 3.5.0 Update 03, 3.5.1 Update 01, 3.5.1 Update 02, 3.5.1 Update 03, 3.6.0, 3.6.0 Update 01, 3.6.0 Update 02, 3.6.0 Update 03, 3.6.0 Update 04, 2.1, 2.2, 3.2, 3.4_DP1, 3.4_DP3, 3.4_DP2, 3.5_DP1, 3.4_DP7, 3.4_DP10, 3.4_DP5, 3.1_DP15, 3.4_DP11, 3.4_DP8, 3.7_DP1, 3.3_DP4, 3.10_DP1, 3.8_DP1, 3.7_DP2, 3.6_DP1, 3.1_DP16, 3.5_DP4, 3.3_DP3, 3.2_DP2, 3.4_DP4, 3.1_DP14, 3.1_DP6, 3.1_DP9, 3.4_DP6, 3.2_DP3, 3.4_DP9, 3.3_DP2, 3.2_DP1, 3.1_DP10, 3.9_DP1, 3.3_DP1, 3.1_DP13, 3.5_DP2, 3.1_DP12, 3.1_DP4, 3.5_DP3, 3.1_DP8, 3.1_DP7, 3.2_DP4, 3.1_DP11, 3.1_DP5, 3.7.0, 3.7.1, 3.7.1 Update 04, 3.7.1 Update 06, 3.7.1 Update 07, 3.7.1 Update 03, 3.7.0 Update 03, 3.7.1 Update 01, 3.7.1 Update 02, 3.7.1 Update 05, 3.8.0, 3.8.1, 3.8.1 Update 02, 3.8.1 Update 04, 3.8.1 Update 01, 3.8.1 Update 03, 3.8.0 Update 01, 3.8.0 Update 02, 3.9.0, 3.9.1, 3.9.1 Update 02, 3.9.1 Update 03, 3.9.1 Update 01, 3.9.1 Update 04, 3.9.0 Update 01, 3.10.0, 3.10.3, 3.10.1, 3.10.2, 3.10 Update 01, 3.10.4, 3.10.4 Update 01, 1.2.6, 1.2.2, 1.2.3, 1.2.5, 1.2.1.2, 1.2.4, 1.2.7, 1.2, 1.2.2.4, 1.2.4.2, 2.0.2, 2.0.4, 2.0.3, 2.0.1, 2.0, 2.0.1.1, 2.0.2.1, 2.0.4.1, 2.0.4.2, 2.1.3, 2.1.1.1, 2.1.1.3, 2.1.1.4, 2.1.2.2, 2.1.2.3, 2.1.3.2, 2.1.3.3, 2.1.3.4, 2.1.3.5, 2.1.4, 2.2.1.1, 2.2.1.2, 2.2.1.3, 2.2.1.4, 3.0, 3.1, 4.1.1, 4.1, 4.1.1.1, 4.1.1.2, 4.0.3, 4.0.1, 4.0.2, 4.0, 4.0.3.1, 5.0.1, 5.0.2, 5.0.2.5, 5.0.2.3, 5.0.2.4, 5.0.2.1, 5.0.2.2, 5.0, 5.0.2.6, 5.1.1, 5.1.2, 5.1.3, 5.1.4, 5.1.4.2, 5.1.4.1, 5.1.4.3, 5.1, 5.1.3.1, 5.1.3.2, 5.1.4.4, 7.0.0, 6.0.0, 6.0.2, 6.0.1, 6.0.2.1, 6.0.1.1, 6.0.3, 6.0.3.1, 6.1.1, 6.1.1.1, 6.1, 6.1.2, 6.1.1.2.2

Timeline

Official Publish: January 17th, 2024
Last Modified: November 13th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

Weaknesses (CWE)