#VU74506 Code Injection in Cisco Systems, Inc products - CVE-2023-20102
Published: April 6, 2023
Stealthwatch Enterprise
Secure Network Analytics Virtual Manager
Stealthwatch Management Console 2200
Secure Network Analytics
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation in the web-based management interface. A remote user can send a specially crafted HTTP request and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.