A vulnerability in Cisco Intersight Virtual Appliance could allow an unauthenticated, adjacent attacker to access internal HTTP services that are otherwise inaccessible.
This vulnerability is due to insufficient restrictions on internally accessible http proxies. An attacker could exploit this vulnerability by submitting a crafted CLI command. A successful exploit could allow the attacker access to internal subnets beyond the sphere of their intended access level.
References
Link | Resource |
---|---|
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-intersight-forward-C45ncgqb | Patch Vendor Advisory |
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-intersight-forward-C45ncgqb | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 07:40
Type | Values Removed | Values Added |
---|---|---|
References | () https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-intersight-forward-C45ncgqb - Patch, Vendor Advisory |
25 Aug 2023, 16:32
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-intersight-forward-C45ncgqb - Patch, Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.3 |
CPE | cpe:2.3:a:cisco:intersight_connected_virtual_appliance:-:*:*:*:*:*:*:* cpe:2.3:a:cisco:intersight_assist:-:*:*:*:*:*:*:* cpe:2.3:a:cisco:intersight_private_virtual_appliance:-:*:*:*:*:*:*:* cpe:2.3:a:cisco:intersight_virtual_appliance:*:*:*:*:*:*:*:* |
|
CWE | CWE-77 | |
First Time |
Cisco intersight Assist
Cisco intersight Private Virtual Appliance Cisco intersight Virtual Appliance Cisco intersight Connected Virtual Appliance Cisco |
16 Aug 2023, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-08-16 22:15
Updated : 2024-11-21 07:40
NVD link : CVE-2023-20237
Mitre link : CVE-2023-20237
CVE.ORG link : CVE-2023-20237
JSON object : View
Products Affected
cisco
- intersight_private_virtual_appliance
- intersight_virtual_appliance
- intersight_connected_virtual_appliance
- intersight_assist