CVE-2023-20217

MEDIUM

Cisco ThousandEyes Enterprise Agent - Privilege Escalation

Title source: llm
STIX 2.1

Description

A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent, Virtual Appliance installation type, could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient input validation by the operating system CLI. An attacker could exploit this vulnerability by issuing certain commands using sudo. A successful exploit could allow the attacker to view arbitrary files as root on the underlying operating system. The attacker must have valid credentials on the affected device.

Scores

CVSS v3 5.5
EPSS 0.0005
EPSS Percentile 15.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-250
Status published
Products (2)
cisco/thousandeyes_enterprise_agent < 0.230
cisco/thousandeyes_recorder
Published Aug 16, 2023
Tracked Since Feb 18, 2026