Vulnerability Description
A vulnerability in TACACS+ and RADIUS remote authentication for Cisco NX-OS Software could allow an unauthenticated, local attacker to cause an affected device to unexpectedly reload. This vulnerability is due to incorrect input validation when processing an authentication attempt if the directed request option is enabled for TACACS+ or RADIUS. An attacker could exploit this vulnerability by entering a crafted string at the login prompt of an affected device. A successful exploit could allow the attacker to cause the affected device to unexpectedly reload, resulting in a denial of service (DoS) condition.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Nx-Os | 9.3\(11\) |
| Cisco | Nexus 3048 | - |
| Cisco | Nexus 31108Pc-V | - |
| Cisco | Nexus 31108Tc-V | - |
| Cisco | Nexus 31128Pq | - |
| Cisco | Nexus 3132C-Z | - |
| Cisco | Nexus 3132Q-V | - |
| Cisco | Nexus 3132Q-Xl | - |
| Cisco | Nexus 3164Q | - |
| Cisco | Nexus 3172Pq | - |
| Cisco | Nexus 3172Pq-Xl | - |
| Cisco | Nexus 3172Tq | - |
| Cisco | Nexus 3172Tq-32T | - |
| Cisco | Nexus 3172Tq-Xl | - |
| Cisco | Nexus 3232 | - |
| Cisco | Nexus 3264C-E | - |
| Cisco | Nexus 3264Q | - |
| Cisco | Nexus 3408-S | - |
| Cisco | Nexus 34180Yc | - |
| Cisco | Nexus 34200Yc-Sm | - |
Related Weaknesses (CWE)
References
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/ciVendor Advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/ciVendor Advisory
FAQ
What is CVE-2023-20168?
CVE-2023-20168 is a vulnerability with a CVSS score of 7.1 (HIGH). A vulnerability in TACACS+ and RADIUS remote authentication for Cisco NX-OS Software could allow an unauthenticated, local attacker to cause an affected device to unexpectedly reload. This vulnerabili...
How severe is CVE-2023-20168?
CVE-2023-20168 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-20168?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Nx-Os, Cisco Nexus 3048, Cisco Nexus 31108Pc-V, Cisco Nexus 31108Tc-V, Cisco Nexus 31128Pq.