PT-2023-4616 · Cisco · Cisco Intersight Virtual Appliance

Andrew Kim

·

Publicado

2023-08-16

·

Atualizado

2024-01-25

·

CVE-2023-20237

CVSS v3.1

4.3

Média

VetorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cisco Intersight Virtual Appliance (affected versions not specified)
Description A vulnerability in Cisco Intersight Virtual Appliance could allow an unauthenticated, adjacent attacker to access internal HTTP services that are otherwise inaccessible. This vulnerability is due to insufficient restrictions on internally accessible http proxies. An attacker could exploit this vulnerability by submitting a crafted CLI command. A successful exploit could allow the attacker access to internal subnets beyond the sphere of their intended access level.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Command Injection

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-05023
CVE-2023-20237

Produtos afetados

Cisco Intersight Virtual Appliance