We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2023-20050

Cisco NX-OS Software CLI Command Injection Vulnerability



Description

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of arguments that are passed to specific CLI commands. An attacker could exploit this vulnerability by including crafted input as the argument of an affected command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of the currently logged-in user.

Reserved 2022-10-27 | Published 2023-02-23 | Updated 2024-10-25 | Assigner cisco


MEDIUM: 4.4CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Problem types

CWE-78

Product status

Any version
affected

References

sec.cloudapps.cisco.com/...sco-sa-nxos-cli-cmdinject-euQVK9u (20230222 Cisco NX-OS Software CLI Command Injection Vulnerability) vendor-advisory

cve.org (CVE-2023-20050)

nvd.nist.gov (CVE-2023-20050)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2023-20050

Support options

Helpdesk Chat, Email, Knowledgebase