CVE Database
/

CVE-2023-20237

Back to search

CVE-2023-20237

Published: Aug 16, 2023

Modified: Aug 2, 2024

PUBLISHED

CVSS v3.1

4.3

MEDIUM

Description

A vulnerability in Cisco Intersight Virtual Appliance could allow an unauthenticated, adjacent attacker to access internal HTTP services that are otherwise inaccessible. This vulnerability is due to insufficient restrictions on internally accessible http proxies. An attacker could exploit this vulnerability by submitting a crafted CLI command. A successful exploit could allow the attacker access to internal subnets beyond the sphere of their intended access level.

VendorProductVersions

Cisco

Cisco Intersight Virtual Appliance

affected
1.0.9-503
affected
1.0.9-536
affected
1.0.9-538
affected
1.0.9-558
affected
1.0.9-561

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Attack Vector

Adjacent

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

None

Integrity

Low

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2023-20237 | MEDIUM (4.3) - Security Vulnerability | QwikSec