7.4

CVE-2023-20185

A vulnerability in the Cisco ACI Multi-Site CloudSec encryption feature of Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an unauthenticated, remote attacker to read or modify intersite encrypted traffic.

 This vulnerability is due to an issue with the implementation of the ciphers that are used by the CloudSec encryption feature on affected switches. An attacker with an on-path position between the ACI sites could exploit this vulnerability by intercepting intersite encrypted traffic and using cryptanalytic techniques to break the encryption. A successful exploit could allow the attacker to read or modify the traffic that is transmitted between the sites.

 Cisco has not released and will not release software updates that address this vulnerability.

Data is provided by the National Vulnerability Database (NVD)
CiscoNx-os Version14.0(1h)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version14.0(2c)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version14.0(3c)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version14.0(3d)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version14.1(1i)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version14.1(1j)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version14.1(1k)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version14.1(1l)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version14.1(2g)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version14.1(2m)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version14.1(2o)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version14.1(2s)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version14.1(2u)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version14.1(2w)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version14.1(2x)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version14.2(1i)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version14.2(1j)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version14.2(1l)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version14.2(2e)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version14.2(2f)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version14.2(2g)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version14.2(3j)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version14.2(3l)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version14.2(3n)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version14.2(3q)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version14.2(4i)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version14.2(4k)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version14.2(4o)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version14.2(4p)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version14.2(5k)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version14.2(5l)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version14.2(5n)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version14.2(6d)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version14.2(6g)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version14.2(6h)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version14.2(6l)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version14.2(6o)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version14.2(7f)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version14.2(7l)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version14.2(7q)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version14.2(7r)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version14.2(7s)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version14.2(7t)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version14.2(7u)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version14.2(7v)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version14.2(7w)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version15.0(1k)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version15.0(1l)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version15.0(2e)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version15.0(2h)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version15.1(1h)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version15.1(2e)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version15.1(3e)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version15.1(4c)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version15.2(1g)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version15.2(2e)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version15.2(2f)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version15.2(2g)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version15.2(2h)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version15.2(3e)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version15.2(3f)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version15.2(3g)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version15.2(4d)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version15.2(4e)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version15.2(4f)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version15.2(5c)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version15.2(5d)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version15.2(5e)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version15.2(6e)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version15.2(6g)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version15.2(7f)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version15.2(7g)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version15.2(8d)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version16.0(1g)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version16.0(1j)
   CiscoNexus 9000 In Aci Mode Version-
CiscoNx-os Version16.0(2h)
   CiscoNexus 9000 In Aci Mode Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.14% 0.346
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.4 2.2 5.2
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
psirt@cisco.com 7.4 2.2 5.2
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CWE-326 Inadequate Encryption Strength

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

CWE-330 Use of Insufficiently Random Values

The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.