Vulnslist

Cisco vulnerabilities by product, model, software, and advisory.

CVE-2023-20186

A vulnerability in the Authentication, Authorization, and Accounting (AAA) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to bypass command authorization and copy files to or from the file system of an affected device using the Secure Copy Protocol (SCP). This vulnerability is due to incorrect processing of SCP commands in AAA command authorization checks. An attacker with valid credentials and level 15 privileges could exploit this vulnerability by using SCP to connect to an affected device from an external machine. A successful exploit could allow the attacker to obtain or change the configuration of the affected device and put files on or retrieve files from the affected device.

SeverityHIGH
CVSS8.0
CWECWE-285
KEV No
Published
Modified

Related Products

Product Advisory Evidence
Cisco IOS cisco-sa-aaascp-Tyj4fEJm Cisco OpenVuln
Cisco IOS XE Software cisco-sa-aaascp-Tyj4fEJm Cisco OpenVuln
Cisco Catalyst 9600 Series Switches cisco-sa-aaascp-Tyj4fEJm Cisco OpenVuln · software-dependent
Cisco Catalyst 9500 Series Switches cisco-sa-aaascp-Tyj4fEJm Cisco OpenVuln · software-dependent
Cisco Catalyst 9400 Series Switches cisco-sa-aaascp-Tyj4fEJm Cisco OpenVuln · software-dependent
Cisco Catalyst 9200 Series Switches cisco-sa-aaascp-Tyj4fEJm Cisco OpenVuln · software-dependent
Cisco Catalyst 9300 Series Switches cisco-sa-aaascp-Tyj4fEJm Cisco OpenVuln · software-dependent