A vulnerability in Cisco Intersight Virtual Appliance could allow an unauthenticated, adjacent attacker to access internal HTTP services that are otherwise inaccessible.
This vulnerability is due to insufficient restrictions on internally accessible http proxies. An attacker could exploit this vulnerability by submitting a crafted CLI command. A successful exploit could allow the attacker access to internal subnets beyond the sphere of their intended access level.
References
Link | Resource |
---|---|
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-intersight-forward-C45ncgqb | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
25 Jan 2024, 17:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-284 |
25 Aug 2023, 16:32
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.3 |
CWE | CWE-77 | |
CPE | cpe:2.3:a:cisco:intersight_connected_virtual_appliance:-:*:*:*:*:*:*:* cpe:2.3:a:cisco:intersight_private_virtual_appliance:-:*:*:*:*:*:*:* cpe:2.3:a:cisco:intersight_assist:-:*:*:*:*:*:*:* cpe:2.3:a:cisco:intersight_virtual_appliance:*:*:*:*:*:*:*:* |
|
References | (MISC) https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-intersight-forward-C45ncgqb - Patch, Vendor Advisory | |
First Time |
Cisco intersight Connected Virtual Appliance
Cisco intersight Private Virtual Appliance Cisco Cisco intersight Virtual Appliance Cisco intersight Assist |
16 Aug 2023, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-08-16 22:15
Updated : 2024-01-25 17:15
NVD link : CVE-2023-20237
Mitre link : CVE-2023-20237
CVE.ORG link : CVE-2023-20237
JSON object : View
Products Affected
cisco
- intersight_connected_virtual_appliance
- intersight_virtual_appliance
- intersight_private_virtual_appliance
- intersight_assist