CVE-2023-20101
CWE-798Published: October 4, 2023· Updated: Jun 17, 2026
Official Description
A vulnerability in Cisco Emergency Responder could allow an unauthenticated, remote attacker to log in to an affected device using the root account, which has default, static credentials that cannot be changed or deleted.
This vulnerability is due to the presence of static user credentials for the root account that are typically reserved for use during development. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and execute arbitrary commands as the root user.
Risk Analysis
Cisco Emergency Responder contains static, hardcoded root credentials that cannot be removed or modified. This critical vulnerability allows an unauthenticated remote attacker to gain full root access to the device, warranting immediate attention due to the CVSS score of 9.8.
There is no known public exploit for this vulnerability, and it is not listed in the CISA KEV catalog. It is remotely exploitable with low attack complexity.
Review Cisco security advisories for available patches or configuration guidance to secure the root account.
Technical Analysis
CVE-2023-20101 can be exploited remotely over the network without requiring physical or adjacent access, significantly expanding the attack surface for threat actors.
The vulnerability requires no privileges and no user interaction, making it a prime target for automated exploitation campaigns and worm-like propagation.
A successful exploit results in complete confidentiality breach (data exposure), full integrity compromise (data manipulation), availability disruption (denial of service), with a CVSS base score of 9.8.
CVSS v3.1 Vector Breakdown
Affected Vendors & Products
Exploit & PoC Resources
Official Patches & Advisories
All References (2)
Quick Facts
Related CVEs (CWE-798)
Recommended Actions
- →Apply vendor patches immediately
- →Monitor CVE-2023-20101 in threat intel feeds
- →Review IDS/IPS signatures for exploitation attempts