CVE-2023-20097 MEDIUM

CVE-2023-20097: Cisco Access Point Software Command Injection Vulnerability

Vendor Cisco
Product Cisco Aironet Access Point Software
Weakness CWE-77
Published March 23, 2023
Last update October 25, 2024

CVSS base score

4.6/10
Attack vector Local
Attack complexity Low
Privileges required High
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N

What the vulnerability does

01Description

A vulnerability in Cisco access points (AP) software could allow an authenticated, local attacker to inject arbitrary commands and execute them with root privileges. This vulnerability is due to improper input validation of commands that are issued from a wireless controller to an AP. An attacker with Administrator access to the CLI of the controller could exploit this vulnerability by issuing a command with crafted arguments. A successful exploit could allow the attacker to gain full root access on the AP.

Key dates

02Disclosure timeline

March 23, 2023 CVE published
October 25, 2024 Record updated