HIGH✓ PATCH🇬🇧 English

CVE-2023-20231

CVSS 8.8v3.1pub. 2023-09-27upd. 2024-11-21

A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injection attack against an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to execute arbitrary Cisco IOS XE Software CLI commands with level 15 privileges. Note: This vulnerability is exploitable only if the attacker obtains the credentials for a Lobby Ambassador account. This account is not configured by default.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Cisco Catalyst 9105ax

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst 9105axi

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst 9105axw

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst 9115ax

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst 9115axe

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst 9115axi

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst 9117ax

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst 9117axi

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst 9120ax

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst 9120axe

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst 9120axi

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst 9120axp

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst 9124ax

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst 9124axd

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst 9124axi

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst 9130ax

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst 9130axe

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst 9130axi

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst 9300

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst 9300 24p A

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst 9300 24p E

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst 9300 24s A

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst 9300 24s E

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst 9300 24t A

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst 9300 24t E

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst 9300 24u A

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst 9300 24u E

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst 9300 24ux A

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst 9300 24ux E

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst 9300 48p A

    HW
    Cisco
    wszystkie wersje
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
Tagi
Command Injection
CWE
Referencje

Powiązane podatności

CVE-2023-20198CRITICAL10.0⚠ KEVPL ✓ten sam produkt

Cisco IOS XE Web UI — nieautoryzowane tworzenie konta z privilege 15

CVE-2018-0151CRITICAL9.8⚠ KEVPL ✓ten sam produkt

Buffer overflow w QoS Cisco IOS/IOS XE — RCE i DoS przez UDP 18999

CVE-2017-3881CRITICAL9.8⚠ KEVPL ✓ten sam produkt

RCE w Cisco IOS/IOS XE – podatność protokołu CMP przez Telnet

CVE-2026-20267CRITICAL9.0PL ✓ten sam produkt

Nieprawidłowa kontrola dostępu w Cisco IOS XE Software (CVE-2026-20267)

CVE-2026-20272CRITICAL9.8PL ✓ten sam produkt

Cisco IOS XE — improper neutralization of special elements (CWE-74)