MEDIUM · 6.0

CVE-2023-20015

A vulnerability in the CLI of Cisco Firepower 4100 Series, Cisco Firepower 9300 Security Appliances, and Cisco UCS 6200, 6300, 6400, and 6500 Series Fabric Interconnects could allow an authenticated, ...

Vulnerability Description

A vulnerability in the CLI of Cisco Firepower 4100 Series, Cisco Firepower 9300 Security Appliances, and Cisco UCS 6200, 6300, 6400, and 6500 Series Fabric Interconnects could allow an authenticated, local attacker to inject unauthorized commands. This vulnerability is due to insufficient input validation of commands supplied by the user. An attacker could exploit this vulnerability by authenticating to a device and submitting crafted input to the affected command. A successful exploit could allow the attacker to execute unauthorized commands within the CLI. An attacker with Administrator privileges could also execute arbitrary commands on the underlying operating system of Cisco UCS 6400 and 6500 Series Fabric Interconnects with root-level privileges.

CVSS Score

6.0

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
CiscoUcs Central Software>= 4.0, < 4.0\(4o\)
CiscoUcs 6536 Firmware-
CiscoUcs 6536-
CiscoUcs 64108 Firmware-
CiscoUcs 64108-
CiscoUcs 6454 Firmware-
CiscoUcs 6454-
CiscoUcs 6200 Firmware-
CiscoUcs 6200-
CiscoUcs 6248Up Firmware-
CiscoUcs 6248Up-
CiscoUcs 6296Up Firmware-
CiscoUcs 6296Up-
CiscoUcs 6300 Firmware-
CiscoUcs 6300-
CiscoUcs 6324 Firmware-
CiscoUcs 6324-
CiscoUcs 6332 Firmware-
CiscoUcs 6332-
CiscoUcs 6332-16Up Firmware-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-20015?

CVE-2023-20015 is a vulnerability with a CVSS score of 6.0 (MEDIUM). A vulnerability in the CLI of Cisco Firepower 4100 Series, Cisco Firepower 9300 Security Appliances, and Cisco UCS 6200, 6300, 6400, and 6500 Series Fabric Interconnects could allow an authenticated, ...

How severe is CVE-2023-20015?

CVE-2023-20015 has been rated MEDIUM with a CVSS base score of 6.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-20015?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Ucs Central Software, Cisco Ucs 6536 Firmware, Cisco Ucs 6536, Cisco Ucs 64108 Firmware, Cisco Ucs 64108.