OS Command Injection in Cisco Systems, Inc products - CVE-2023-20050
Published: February 23, 2023
Vulnerability details
The vulnerability allows a local user to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation in the CLI. A local user can pass specially crafted data to the application and execute arbitrary OS commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Nexus 1000V Switch for Microsoft Hyper-V
Nexus 1000V Switch for VMware vSphere
Cisco MDS 9000 Series Multilayer Switches
Nexus 5500 Platform Switches
Nexus 5600 Platform Switches
Nexus 6000 Series Switches
Nexus 7000 Series Switches
Cisco Nexus 3000 Series Switches
Cisco Nexus 9000 Series Switches NX-OS Mode
Cisco NX-OS
PowerFlex Appliance
PowerFlex rack
Connectrix Cisco MDS 9000
How to mitigate CVE-2023-20050
Nexus 5500 Platform Switches - update to 7.3(13)N1(1)
Nexus 5600 Platform Switches - update to 7.3(13)N1(1)
Nexus 6000 Series Switches - update to 7.3(13)N1(1)
Nexus 7000 Series Switches - update to 8.4(7)
Cisco Nexus 3000 Series Switches - addressed in versions 9.3(11), 10.3(2)
Cisco Nexus 9000 Series Switches NX-OS Mode - addressed in versions 9.3(11), 10.3(2)
PowerFlex Appliance - update to IC 38.363.02
PowerFlex rack - update to 3.6.3.2
Connectrix Cisco MDS 9000 - addressed in versions 8.4(2f), 9.3(2)