6
CVE-2023-20234
- EPSS 0.02%
- Veröffentlicht 23.08.2023 19:15:08
- Zuletzt bearbeitet 21.11.2024 07:40:57
- Quelle psirt@cisco.com
- CVE-Watchlists
- Unerledigt
A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to create a file or overwrite any file on the filesystem of an affected device, including system files. The vulnerability occurs because there is no validation of parameters when a specific CLI command is used. An attacker could exploit this vulnerability by authenticating to an affected device and using the command at the CLI. A successful exploit could allow the attacker to overwrite any file on the disk of the affected device, including system files. The attacker must have valid administrative credentials on the affected device to exploit this vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Firepower Extensible Operating System Version-
Cisco ≫ Firepower 1000 Version-
Cisco ≫ Firepower 1010 Version-
Cisco ≫ Firepower 1020 Version-
Cisco ≫ Firepower 1030 Version-
Cisco ≫ Firepower 1040 Version-
Cisco ≫ Firepower 2100 Version-
Cisco ≫ Firepower 2110 Version-
Cisco ≫ Firepower 2120 Version-
Cisco ≫ Firepower 2130 Version-
Cisco ≫ Firepower 2140 Version-
Cisco ≫ Firepower 4100 Version-
Cisco ≫ Firepower 4110 Version-
Cisco ≫ Firepower 4110 Next-generation Firewall Version-
Cisco ≫ Firepower 4112 Version-
Cisco ≫ Firepower 4115 Version-
Cisco ≫ Firepower 4120 Version-
Cisco ≫ Firepower 4120 Next-generation Firewall Version-
Cisco ≫ Firepower 4125 Version-
Cisco ≫ Firepower 4140 Version-
Cisco ≫ Firepower 4140 Next-generation Firewall Version-
Cisco ≫ Firepower 4145 Version-
Cisco ≫ Firepower 4150 Version-
Cisco ≫ Firepower 4150 Next-generation Firewall Version-
Cisco ≫ Firepower 9300 Version-
Cisco ≫ Firepower 9300 Security Appliance Version-
Cisco ≫ Firepower 9300 Sm-24 Version-
Cisco ≫ Firepower 9300 Sm-36 Version-
Cisco ≫ Firepower 9300 Sm-40 Version-
Cisco ≫ Firepower 9300 Sm-44 Version-
Cisco ≫ Firepower 9300 Sm-44 X 3 Version-
Cisco ≫ Firepower 9300 Sm-48 Version-
Cisco ≫ Firepower 9300 Sm-56 Version-
Cisco ≫ Firepower 9300 Sm-56 X 3 Version-
Cisco ≫ Firepower 9300 With 1 Sm-24 Module Version-
Cisco ≫ Firepower 9300 With 1 Sm-36 Module Version-
Cisco ≫ Firepower 9300 With 1 Sm-44 Module Version-
Cisco ≫ Firepower 9300 With 3 Sm-44 Module Version-
Cisco ≫ Secure Firewall 3105 Version-
Cisco ≫ Secure Firewall 3110 Version-
Cisco ≫ Secure Firewall 3120 Version-
Cisco ≫ Secure Firewall 3130 Version-
Cisco ≫ Secure Firewall 3140 Version-
Cisco ≫ Firepower 1010 Version-
Cisco ≫ Firepower 1020 Version-
Cisco ≫ Firepower 1030 Version-
Cisco ≫ Firepower 1040 Version-
Cisco ≫ Firepower 2100 Version-
Cisco ≫ Firepower 2110 Version-
Cisco ≫ Firepower 2120 Version-
Cisco ≫ Firepower 2130 Version-
Cisco ≫ Firepower 2140 Version-
Cisco ≫ Firepower 4100 Version-
Cisco ≫ Firepower 4110 Version-
Cisco ≫ Firepower 4110 Next-generation Firewall Version-
Cisco ≫ Firepower 4112 Version-
Cisco ≫ Firepower 4115 Version-
Cisco ≫ Firepower 4120 Version-
Cisco ≫ Firepower 4120 Next-generation Firewall Version-
Cisco ≫ Firepower 4125 Version-
Cisco ≫ Firepower 4140 Version-
Cisco ≫ Firepower 4140 Next-generation Firewall Version-
Cisco ≫ Firepower 4145 Version-
Cisco ≫ Firepower 4150 Version-
Cisco ≫ Firepower 4150 Next-generation Firewall Version-
Cisco ≫ Firepower 9300 Version-
Cisco ≫ Firepower 9300 Security Appliance Version-
Cisco ≫ Firepower 9300 Sm-24 Version-
Cisco ≫ Firepower 9300 Sm-36 Version-
Cisco ≫ Firepower 9300 Sm-40 Version-
Cisco ≫ Firepower 9300 Sm-44 Version-
Cisco ≫ Firepower 9300 Sm-44 X 3 Version-
Cisco ≫ Firepower 9300 Sm-48 Version-
Cisco ≫ Firepower 9300 Sm-56 Version-
Cisco ≫ Firepower 9300 Sm-56 X 3 Version-
Cisco ≫ Firepower 9300 With 1 Sm-24 Module Version-
Cisco ≫ Firepower 9300 With 1 Sm-36 Module Version-
Cisco ≫ Firepower 9300 With 1 Sm-44 Module Version-
Cisco ≫ Firepower 9300 With 3 Sm-44 Module Version-
Cisco ≫ Secure Firewall 3105 Version-
Cisco ≫ Secure Firewall 3110 Version-
Cisco ≫ Secure Firewall 3120 Version-
Cisco ≫ Secure Firewall 3130 Version-
Cisco ≫ Secure Firewall 3140 Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.02% | 0.039 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6 | 0.8 | 5.2 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
|
| psirt@cisco.com | 4.4 | 0.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
|
CWE-73 External Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.
CWE-732 Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.