PT-2023-4616 · Cisco · Cisco Intersight Virtual Appliance
Andrew Kim
·
Published
2023-08-16
·
Updated
2024-01-25
·
CVE-2023-20237
CVSS v3.1
4.3
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Intersight Virtual Appliance (affected versions not specified)
Description
A vulnerability in Cisco Intersight Virtual Appliance could allow an unauthenticated, adjacent attacker to access internal HTTP services that are otherwise inaccessible. This vulnerability is due to insufficient restrictions on internally accessible http proxies. An attacker could exploit this vulnerability by submitting a crafted CLI command. A successful exploit could allow the attacker access to internal subnets beyond the sphere of their intended access level.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Command Injection
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Intersight Virtual Appliance