PT-2023-1621 · Cisco · Cisco Nexus 9300-Fx3 Series Fabric Extender+2
Published
2023-02-22
·
Updated
2023-03-13
·
CVE-2023-20012
CVSS v3.1
5.3
Medium
| Vector | AV:P/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco Unified Computing System (UCS) Manager versions (affected versions not specified)
Cisco Nexus 9000 Series (affected versions not specified)
Cisco Nexus 9300-FX3 Series Fabric Extender (FEX) (affected versions not specified)
Description
The issue is related to weaknesses in the authentication procedure when checking passwords. It could allow an attacker to cause a denial of service condition. An unauthenticated attacker with physical access could bypass authentication by logging in to the console port on an affected device, potentially causing a device reboot. The vulnerability is due to the improper implementation of the password validation function, specifically the
password validation function.Recommendations
For Cisco Unified Computing System (UCS) Manager, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For Cisco Nexus 9000 Series, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For Cisco Nexus 9300-FX3 Series Fabric Extender (FEX), consider restricting physical access to the console port as a temporary workaround until a patch is available.
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Nexus 9000 Series
Cisco Nexus 9300-Fx3 Series Fabric Extender
Cisco Unified Computing System (Ucs) Manager