CVE-2023-20066
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD
Description
A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to perform a directory traversal and access resources that are outside the filesystem mountpoint of the web UI. This vulnerability is due to an insufficient security configuration. An attacker could exploit this vulnerability by sending a crafted request to the web UI. A successful exploit could allow the attacker to gain read access to files that are outside the filesystem mountpoint of the web UI. Note: These files are located on a restricted filesystem that is maintained for the web UI. There is no ability to write to any files on this filesystem.
Affected (3)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 16.12.3 |
| Running on/with | Platform Versions |
|---|---|
Cisco 1000 Integrated Services Router | All versions |
Cisco 1100 4g Integrated Services Router | All versions |
Cisco 1100 4p Integrated Services Router | All versions |
Cisco 1100 6g Integrated Services Router | All versions |
Cisco 1100 8p Integrated Services Router | All versions |
Cisco 1100 Integrated Services Router | All versions |
Cisco 1101 4p Integrated Services Router | All versions |
Cisco 1101 Integrated Services Router | All versions |
Cisco 1109 2p Integrated Services Router | All versions |
Cisco 1109 4p Integrated Services Router | All versions |
Cisco 1109 Integrated Services Router | All versions |
Cisco 1111x 8p Integrated Services Router | All versions |
Cisco 1111x Integrated Services Router | All versions |
Cisco 111x Integrated Services Router | All versions |
Cisco 1120 Integrated Services Router | All versions |
Cisco 1131 Integrated Services Router | All versions |
Cisco 1160 Integrated Services Router | All versions |
Cisco 4000 Integrated Services Router | All versions |
Cisco 4221 Integrated Services Router | All versions |
Cisco 4321 Integrated Services Router | All versions |
Cisco 4331 Integrated Services Router | All versions |
Cisco 4351 Integrated Services Router | All versions |
Cisco 4431 Integrated Services Router | All versions |
Cisco 4451 X Integrated Services Router | All versions |
Cisco 4451 Integrated Services Router | All versions |
Cisco 4461 Integrated Services Router | All versions |
Cisco 8101 32fh | All versions |
Cisco 8101 32h | All versions |
Cisco 8102 64h | All versions |
Cisco 8201 | All versions |
Cisco 8201 32fh | All versions |
Cisco 8202 | All versions |
Cisco 8800 12 Slot | All versions |
Cisco 8800 18 Slot | All versions |
Cisco 8800 4 Slot | All versions |
Cisco 8800 8 Slot | All versions |
Cisco 8804 | All versions |
Cisco 8808 | All versions |
Cisco 8812 | All versions |
Cisco 8818 | All versions |
Cisco 8831 | All versions |
Cisco 9800 40 | All versions |
Cisco 9800 80 | All versions |
Cisco 9800 Cl | All versions |
Cisco 9800 L | All versions |
Cisco Asr 1000 | All versions |
Cisco Asr 1000 Esp100 | All versions |
Cisco Asr 1000 Esp100 X | All versions |
Cisco Asr 1000 Esp200 X | All versions |
Cisco Asr 1001 | All versions |
Cisco Asr 1001 Hx | All versions |
Cisco Asr 1001 Hx R | All versions |
Cisco Asr 1001 X | All versions |
Cisco Asr 1001 X R | All versions |
Cisco Asr 1002 | All versions |
Cisco Asr 1002 Hx | All versions |
Cisco Asr 1002 Hx R | All versions |
Cisco Asr 1002 X | All versions |
Cisco Asr 1002 X R | All versions |
Cisco Asr 1004 | All versions |
Cisco Asr 1006 | All versions |
Cisco Asr 1006 X | All versions |
Cisco Asr 1009 X | All versions |
Cisco Asr 1013 | All versions |
Cisco Asr 1023 | All versions |
Cisco Asr 900 | All versions |
Cisco Asr 9000 | All versions |
Cisco Asr 9000v | All versions |
Cisco Asr 9001 | All versions |
Cisco Asr 9006 | All versions |
Cisco Asr 901 12c F D | All versions |
Cisco Asr 901 12c Ft D | All versions |
Cisco Asr 901 4c F D | All versions |
Cisco Asr 901 4c Ft D | All versions |
Cisco Asr 901 6cz F A | All versions |
Cisco Asr 901 6cz F D | All versions |
Cisco Asr 901 6cz Fs A | All versions |
Cisco Asr 901 6cz Fs D | All versions |
Cisco Asr 901 6cz Ft A | All versions |
Cisco Asr 901 6cz Ft D | All versions |
Cisco Asr 9010 | All versions |
Cisco Asr 901s 2sg F Ah | All versions |
Cisco Asr 901s 2sg F D | All versions |
Cisco Asr 901s 3sg F Ah | All versions |
Cisco Asr 901s 3sg F D | All versions |
Cisco Asr 901s 4sg F D | All versions |
Cisco Asr 902 | All versions |
Cisco Asr 902u | All versions |
Cisco Asr 903 | All versions |
Cisco Asr 907 | All versions |
Cisco Asr 914 | All versions |
Cisco Asr 920 10sz Pd | All versions |
Cisco Asr 920 10sz Pd R | All versions |
Cisco Asr 920 12cz A | All versions |
Cisco Asr 920 12cz A R | All versions |
Cisco Asr 920 12cz D | All versions |
Cisco Asr 920 12cz D R | All versions |
Cisco Asr 920 12sz Im | All versions |
Cisco Asr 920 12sz Im R | All versions |
Cisco Asr 920 24sz Im | All versions |
Cisco Asr 920 24sz Im R | All versions |
Cisco Asr 920 24sz M | All versions |
Cisco Asr 920 24sz M R | All versions |
Cisco Asr 920 24tz M | All versions |
Cisco Asr 920 24tz M R | All versions |
Cisco Asr 920 4sz A | All versions |
Cisco Asr 920 4sz A R | All versions |
Cisco Asr 920 4sz D | All versions |
Cisco Asr 920 4sz D R | All versions |
Cisco Asr 920u 12sz Im | All versions |
Cisco Asr 9901 | All versions |
Cisco Asr 9902 | All versions |
Cisco Asr 9903 | All versions |
Cisco Asr 9904 | All versions |
Cisco Asr 9906 | All versions |
Cisco Asr 9910 | All versions |
Cisco Asr 9912 | All versions |
Cisco Asr 9920 | All versions |
Cisco Asr 9922 | All versions |
Cisco Catalyst 3850 | All versions |
Cisco Catalyst 3850 12s E | All versions |
Cisco Catalyst 3850 12s S | All versions |
Cisco Catalyst 3850 12x48u | All versions |
Cisco Catalyst 3850 12xs E | All versions |
Cisco Catalyst 3850 12xs S | All versions |
Cisco Catalyst 3850 16xs E | All versions |
Cisco Catalyst 3850 16xs S | All versions |
Cisco Catalyst 3850 24p E | All versions |
Cisco Catalyst 3850 24p L | All versions |
Cisco Catalyst 3850 24p S | All versions |
Cisco Catalyst 3850 24pw S | All versions |
Cisco Catalyst 3850 24s E | All versions |
Cisco Catalyst 3850 24s S | All versions |
Cisco Catalyst 3850 24t E | All versions |
Cisco Catalyst 3850 24t L | All versions |
Cisco Catalyst 3850 24t S | All versions |
Cisco Catalyst 3850 24u | All versions |
Cisco Catalyst 3850 24u E | All versions |
Cisco Catalyst 3850 24u L | All versions |
Cisco Catalyst 3850 24u S | All versions |
Cisco Catalyst 3850 24xs | All versions |
Cisco Catalyst 3850 24xs E | All versions |
Cisco Catalyst 3850 24xs S | All versions |
Cisco Catalyst 3850 24xu | All versions |
Cisco Catalyst 3850 24xu E | All versions |
Cisco Catalyst 3850 24xu L | All versions |
Cisco Catalyst 3850 24xu S | All versions |
Cisco Catalyst 3850 32xs E | All versions |
Cisco Catalyst 3850 32xs S | All versions |
Cisco Catalyst 3850 48f E | All versions |
Cisco Catalyst 3850 48f L | All versions |
Cisco Catalyst 3850 48f S | All versions |
Cisco Catalyst 3850 48p E | All versions |
Cisco Catalyst 3850 48p L | All versions |
Cisco Catalyst 3850 48p S | All versions |
Cisco Catalyst 3850 48pw S | All versions |
Cisco Catalyst 3850 48t E | All versions |
Cisco Catalyst 3850 48t L | All versions |
Cisco Catalyst 3850 48t S | All versions |
Cisco Catalyst 3850 48u | All versions |
Cisco Catalyst 3850 48u E | All versions |
Cisco Catalyst 3850 48u L | All versions |
Cisco Catalyst 3850 48u S | All versions |
Cisco Catalyst 3850 48xs | All versions |
Cisco Catalyst 3850 48xs E | All versions |
Cisco Catalyst 3850 48xs F E | All versions |
Cisco Catalyst 3850 48xs F S | All versions |
Cisco Catalyst 3850 48xs S | All versions |
Cisco Catalyst 3850 Nm 2 40g | All versions |
Cisco Catalyst 3850 Nm 8 10g | All versions |
Cisco Catalyst 8200 | All versions |
Cisco Catalyst 8300 | All versions |
Cisco Catalyst 8300 1n1s 4t2x | All versions |
Cisco Catalyst 8300 1n1s 6t | All versions |
Cisco Catalyst 8300 2n2s 4t2x | All versions |
Cisco Catalyst 8300 2n2s 6t | All versions |
Cisco Catalyst 8500 | All versions |
Cisco Catalyst 8500 4qc | All versions |
Cisco Catalyst 8500l | All versions |
Cisco Catalyst 8510csr | All versions |
Cisco Catalyst 8510msr | All versions |
Cisco Catalyst 8540csr | All versions |
Cisco Catalyst 8540msr | All versions |
Cisco Catalyst 9200 | All versions |
Cisco Catalyst 9200cx | All versions |
Cisco Catalyst 9200l | All versions |
Cisco Catalyst 9300 | All versions |
Cisco Catalyst 9300 24p A | All versions |
Cisco Catalyst 9300 24p E | All versions |
Cisco Catalyst 9300 24s A | All versions |
Cisco Catalyst 9300 24s E | All versions |
Cisco Catalyst 9300 24t A | All versions |
Cisco Catalyst 9300 24t E | All versions |
Cisco Catalyst 9300 24u A | All versions |
Cisco Catalyst 9300 24u E | All versions |
Cisco Catalyst 9300 24ux A | All versions |
Cisco Catalyst 9300 24ux E | All versions |
Cisco Catalyst 9300 48p A | All versions |
Cisco Catalyst 9300 48p E | All versions |
Cisco Catalyst 9300 48s A | All versions |
Cisco Catalyst 9300 48s E | All versions |
Cisco Catalyst 9300 48t A | All versions |
Cisco Catalyst 9300 48t E | All versions |
Cisco Catalyst 9300 48u A | All versions |
Cisco Catalyst 9300 48u E | All versions |
Cisco Catalyst 9300 48un A | All versions |
Cisco Catalyst 9300 48un E | All versions |
Cisco Catalyst 9300 48uxm A | All versions |
Cisco Catalyst 9300 48uxm E | All versions |
Cisco Catalyst 9300l | All versions |
Cisco Catalyst 9300l 24p 4g A | All versions |
Cisco Catalyst 9300l 24p 4g E | All versions |
Cisco Catalyst 9300l 24p 4x A | All versions |
Cisco Catalyst 9300l 24p 4x E | All versions |
Cisco Catalyst 9300l 24t 4g A | All versions |
Cisco Catalyst 9300l 24t 4g E | All versions |
Cisco Catalyst 9300l 24t 4x A | All versions |
Cisco Catalyst 9300l 24t 4x E | All versions |
Cisco Catalyst 9300l 48p 4g A | All versions |
Cisco Catalyst 9300l 48p 4g E | All versions |
Cisco Catalyst 9300l 48p 4x A | All versions |
Cisco Catalyst 9300l 48p 4x E | All versions |
Cisco Catalyst 9300l 48t 4g A | All versions |
Cisco Catalyst 9300l 48t 4g E | All versions |
Cisco Catalyst 9300l 48t 4x A | All versions |
Cisco Catalyst 9300l 48t 4x E | All versions |
Cisco Catalyst 9300l Stack | All versions |
Cisco Catalyst 9300lm | All versions |
Cisco Catalyst 9300x | All versions |
Cisco Catalyst 9400 | All versions |
Cisco Catalyst 9400 Supervisor Engine 1 | All versions |
Cisco Catalyst 9407r | All versions |
Cisco Catalyst 9410r | All versions |
Cisco Catalyst 9500 | All versions |
Cisco Catalyst 9500h | All versions |
Cisco Catalyst 9600 | All versions |
Cisco Catalyst 9600 Supervisor Engine 1 | All versions |
Cisco Catalyst 9600x | All versions |
Cisco Catalyst 9800 | All versions |
Cisco Catalyst 9800 40 | All versions |
Cisco Catalyst 9800 40 Wireless Controller | All versions |
Cisco Catalyst 9800 80 | All versions |
Cisco Catalyst 9800 80 Wireless Controller | All versions |
Cisco Catalyst 9800 Cl | All versions |
Cisco Catalyst 9800 L | All versions |
Cisco Catalyst 9800 L C | All versions |
Cisco Catalyst 9800 L F | All versions |
Cisco Catalyst 9800 Embedded Wireless Controller | All versions |
Cisco Catalyst Ie3200 | All versions |
Cisco Catalyst Ie3200 Rugged Switch | All versions |
Cisco Catalyst Ie3300 | All versions |
Cisco Catalyst Ie3300 Rugged Switch | All versions |
Cisco Catalyst Ie3400 | All versions |
Cisco Catalyst Ie3400 Heavy Duty Switch | All versions |
Cisco Catalyst Ie3400 Rugged Switch | All versions |
Cisco Catalyst Ie9300 | All versions |
Cisco Cbr 8 | All versions |
Cisco Cg418 E | All versions |
Cisco Cg522 E | All versions |
Cisco Esr6300 | All versions |
Cisco Ess 3300 24t Con A | All versions |
Cisco Ess 3300 24t Con E | All versions |
Cisco Ess 3300 24t Ncp A | All versions |
Cisco Ess 3300 24t Ncp E | All versions |
Cisco Ess 3300 Con A | All versions |
Cisco Ess 3300 Con E | All versions |
Cisco Ess 3300 Ncp A | All versions |
Cisco Ess 3300 Ncp E | All versions |
Cisco Ess9300 10x E | All versions |
Cisco Integrated Services Virtual Router | All versions |
Related CWEs
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CWE-23
Relative Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.
References (2)
Source: psirt@cisco.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.