← back
CVE-2023-20043mediumCWE-708

CVE-2023-20043

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.7epss 0.2%
exploitation probability
0.2%top 89% of all CVEs
observed exploitation
nono source reports it
In short

A local user on a device with Cisco CX Cloud Agent can gain full control by exploiting insecure file permissions and running a script with elevated privileges.

Technical detail

CWE-708 vulnerability allows authenticated local attackers to escalate privileges via insecure file permissions on executable scripts; exploitation requires sudo access and results in complete system compromise.

Summary generated and translated by AI from the official description.
A vulnerability in Cisco CX Cloud Agent of could allow an authenticated, local attacker to elevate their privileges. This vulnerability is due to insecure file permissions. An attacker could exploit this vulnerability by calling the script with sudo. A successful exploit could allow the attacker to take complete control of the affected device.
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H