Vulnerability Description
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of arguments that are passed to specific CLI commands. An attacker could exploit this vulnerability by including crafted input as the argument of an affected command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of the currently logged-in user.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Nx-Os | - |
| Cisco | Mds 9000 | - |
| Cisco | Mds 9100 | - |
| Cisco | Mds 9132T | - |
| Cisco | Mds 9134 | - |
| Cisco | Mds 9140 | - |
| Cisco | Mds 9148 | - |
| Cisco | Mds 9148S | - |
| Cisco | Mds 9148T | - |
| Cisco | Mds 9200 | - |
| Cisco | Mds 9216 | - |
| Cisco | Mds 9216A | - |
| Cisco | Mds 9216I | - |
| Cisco | Mds 9222I | - |
| Cisco | Mds 9250I | - |
| Cisco | Mds 9396S | - |
| Cisco | Mds 9396T | - |
| Cisco | Mds 9500 | - |
| Cisco | Mds 9506 | - |
| Cisco | Mds 9509 | - |
Related Weaknesses (CWE)
References
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/ciVendor Advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/ciVendor Advisory
FAQ
What is CVE-2023-20050?
CVE-2023-20050 is a vulnerability with a CVSS score of 4.4 (MEDIUM). A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. This vulnerabili...
How severe is CVE-2023-20050?
CVE-2023-20050 has been rated MEDIUM with a CVSS base score of 4.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-20050?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Nx-Os, Cisco Mds 9000, Cisco Mds 9100, Cisco Mds 9132T, Cisco Mds 9134.