MEDIUM✓ PATCH🇵🇱 Wersja polska

CVE-2023-20115

CVSS 5.4v3.1pub. 2023-08-23upd. 2024-11-21

A vulnerability in the SFTP server implementation for Cisco Nexus 3000 Series Switches and 9000 Series Switches in standalone NX-OS mode could allow an authenticated, remote attacker to download or overwrite files from the underlying operating system of an affected device. This vulnerability is due to a logic error when verifying the user role when an SFTP connection is opened to an affected device. An attacker could exploit this vulnerability by connecting and authenticating via SFTP as a valid, non-administrator user. A successful exploit could allow the attacker to read or overwrite files from the underlying operating system with the privileges of the authenticated user. There are workarounds that address this vulnerability.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
  • Cisco Nexus 3048

    HW
    Cisco
    all versions
  • Cisco Nexus 31108pc V

    HW
    Cisco
    all versions
  • Cisco Nexus 31108tc V

    HW
    Cisco
    all versions
  • Cisco Nexus 31128pq

    HW
    Cisco
    all versions
  • Cisco Nexus 3132c Z

    HW
    Cisco
    all versions
  • Cisco Nexus 3132q V

    HW
    Cisco
    all versions
  • Cisco Nexus 3132q Xl

    HW
    Cisco
    all versions
  • Cisco Nexus 3164q

    HW
    Cisco
    all versions
  • Cisco Nexus 3172pq

    HW
    Cisco
    all versions
  • Cisco Nexus 3172pq Xl

    HW
    Cisco
    all versions
  • Cisco Nexus 3172tq

    HW
    Cisco
    all versions
  • Cisco Nexus 3172tq 32t

    HW
    Cisco
    all versions
  • Cisco Nexus 3172tq Xl

    HW
    Cisco
    all versions
  • Cisco Nexus 3232c

    HW
    Cisco
    all versions
  • Cisco Nexus 3264c E

    HW
    Cisco
    all versions
  • Cisco Nexus 3264q

    HW
    Cisco
    all versions
  • Cisco Nexus 3408 S

    HW
    Cisco
    all versions
  • Cisco Nexus 34180yc

    HW
    Cisco
    all versions
  • Cisco Nexus 34200yc Sm

    HW
    Cisco
    all versions
  • Cisco Nexus 3432d S

    HW
    Cisco
    all versions
  • Cisco Nexus 3464c

    HW
    Cisco
    all versions
  • Cisco Nexus 3524

    HW
    Cisco
    all versions
  • Cisco Nexus 3524 X

    HW
    Cisco
    all versions
  • Cisco Nexus 3524 Xl

    HW
    Cisco
    all versions
  • Cisco Nexus 3548

    HW
    Cisco
    all versions
  • Cisco Nexus 3548 X

    HW
    Cisco
    all versions
  • Cisco Nexus 3548 Xl

    HW
    Cisco
    all versions
  • Cisco Nexus 36180yc R

    HW
    Cisco
    all versions
  • Cisco Nexus 3636c R

    HW
    Cisco
    all versions
  • Cisco Nexus 9000v

    HW
    Cisco
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2021-1361CRITICAL9.8PL ✓same product

Cisco NX-OS: nieautoryzowany dostęp do plików przez port TCP 9075

CVE-2019-1804CRITICAL9.8PL ✓same product

Domyślna para kluczy SSH w Cisco Nexus 9000 ACI umożliwia dostęp root

CVE-2018-0310CRITICAL9.8PL ✓same product

Cisco FXOS/NX-OS: buffer overread w Cisco Fabric Services umożliwia DoS lub wyciek danych

CVE-2018-0301CRITICAL9.8PL ✓same product

Cisco NX-OS NX-API — buffer overflow umożliwiający RCE jako root

CVE-2016-1453CRITICAL9.8PL ✓same product

Buffer overflow w funkcji OTV GRE w Cisco NX-OS na urządzeniach Nexus