#VU72510 Improper Authentication in Cisco Systems, Inc products - CVE-2023-20012
Published: February 23, 2023
Cisco Nexus 9300-FX3 Series Fabric Extender (FEX)
UCS 6400 Series Fabric Interconnects
UCS 6500 Series Fabric Interconnects
N9K-C93180YC-FX3
N9K-C93180YC-FX3S
Cisco UCS
Cisco Systems, Inc
Description
The vulnerability allows a local attacker to bypass authentication process.
The vulnerability exists due to the improper implementation of the password validation function. An attacker with physical access can bypass authentication and execute a limited set of commands local to the FEX, leading to a device reboot and denial of service (DoS) condition.