PT-2023-4522 · Cisco · Cisco Intersight Private Virtual Appliance

Logan Sanderson

·

Publicado

2023-08-16

·

Atualizado

2024-01-25

·

CVE-2023-20013

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco Intersight Private Virtual Appliance (affected versions not specified)
Description The issue is due to insufficient input validation when extracting uploaded software packages, allowing an authenticated, remote attacker with Administrator privileges to execute arbitrary commands using root-level privileges. This can be achieved by uploading a crafted software package to an affected device. A successful exploit could allow the attacker to execute commands on the underlying operating system with root-level privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-04925
CVE-2023-20013

Produtos afetados

Cisco Intersight Private Virtual Appliance