PT-2023-4616 · Cisco · Cisco Intersight Virtual Appliance

Andrew Kim

·

Published

2023-08-16

·

Updated

2024-01-25

·

CVE-2023-20237

CVSS v3.1

4.3

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cisco Intersight Virtual Appliance (affected versions not specified)
Description A vulnerability in Cisco Intersight Virtual Appliance could allow an unauthenticated, adjacent attacker to access internal HTTP services that are otherwise inaccessible. This vulnerability is due to insufficient restrictions on internally accessible http proxies. An attacker could exploit this vulnerability by submitting a crafted CLI command. A successful exploit could allow the attacker access to internal subnets beyond the sphere of their intended access level.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Command Injection

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2023-05023
CVE-2023-20237

Affected Products

Cisco Intersight Virtual Appliance