← Back

CVE-2023-20015

nvd nist
Published: Feb 23, 2023Modified: Nov 21, 2024

JSON object

Loading...
6.7
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.8 / Impact: 5.9
Source: NVD

Description

A vulnerability in the CLI of Cisco Firepower 4100 Series, Cisco Firepower 9300 Security Appliances, and Cisco UCS 6200, 6300, 6400, and 6500 Series Fabric Interconnects could allow an authenticated, local attacker to inject unauthorized commands. This vulnerability is due to insufficient input validation of commands supplied by the user. An attacker could exploit this vulnerability by authenticating to a device and submitting crafted input to the affected command. A successful exploit could allow the attacker to execute unauthorized commands within the CLI. An attacker with Administrator privileges could also execute arbitrary commands on the underlying operating system of Cisco UCS 6400 and 6500 Series Fabric Interconnects with root-level privileges.

Affected (14)

12 products
Ucs 6536 Firmware
Ucs 64108 Firmware
Ucs 6454 Firmware
Ucs 6200 Firmware
Ucs 6248up Firmware
Ucs 6296up Firmware
Ucs 6300 Firmware
Ucs 6324 Firmware
Ucs 6332 Firmware
Ucs 6332 16up Firmware
Ucs Central Software
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
Ucs 6536
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
Ucs 64108
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
Ucs 6454
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
Ucs 6200
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
Ucs 6248up
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
Ucs 6296up
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
Ucs 6300
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
Ucs 6324
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
Ucs 6332
All versions
Configuration J
4 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Cisco
From 4.0 to 4.0\(4o\)
From 4.1 to 4.1\(3k\)
From 4.2 to 4.2\(2d\)
Running on/withPlatform Versions
Cisco
Ucs 6332 16up
All versions
Configuration K
1 vulnerable · 17 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
Firepower 4100
All versions
Cisco
Firepower 4110
All versions
Cisco
Firepower 4112
All versions
Cisco
Firepower 4115
All versions
Cisco
Firepower 4120
All versions
Cisco
Firepower 4125
All versions
Cisco
Firepower 4140
All versions
Cisco
Firepower 4145
All versions
Cisco
Firepower 4150
All versions
Cisco
Firepower 9300 Sm 24
All versions
Cisco
Firepower 9300 Sm 36
All versions
Cisco
Firepower 9300 Sm 40
All versions
Cisco
Firepower 9300 Sm 44
All versions
Cisco
Firepower 9300 Sm 44 X 3
All versions
Cisco
Firepower 9300 Sm 48
All versions
Cisco
Firepower 9300 Sm 56
All versions
Cisco
Firepower 9300 Sm 56 X 3
All versions

Timeline

No history available yet.