OS Command Injection in Cisco Systems, Inc products - CVE-2023-20050

 

OS Command Injection in Cisco Systems, Inc products - CVE-2023-20050

Published: February 23, 2023


Vulnerability identifier: #VU72512
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-20050
CWE-ID: CWE-78
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute arbitrary shell commands on the target system.

The vulnerability exists due to improper input validation in the CLI. A local user can pass specially crafted data to the application and execute arbitrary OS commands on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Nexus 1000 Virtual Edge for VMware vSphere
Nexus 1000V Switch for Microsoft Hyper-V
Nexus 1000V Switch for VMware vSphere
Cisco MDS 9000 Series Multilayer Switches
Nexus 5500 Platform Switches
Nexus 5600 Platform Switches
Nexus 6000 Series Switches
Nexus 7000 Series Switches
Cisco Nexus 3000 Series Switches
Cisco Nexus 9000 Series Switches NX-OS Mode
Cisco NX-OS
PowerFlex Appliance
PowerFlex rack
Connectrix Cisco MDS 9000

How to mitigate CVE-2023-20050

Install updates from vendor's website.

Cisco MDS 9000 Series Multilayer Switches - addressed in versions 8.4(2f)S17, 9.3(0.15)S0, 9.3(1)MSM(0.96), 9.3(1.71)S0, 9.3(2)
Nexus 5500 Platform Switches - update to 7.3(13)N1(1)
Nexus 5600 Platform Switches - update to 7.3(13)N1(1)
Nexus 6000 Series Switches - update to 7.3(13)N1(1)
Nexus 7000 Series Switches - update to 8.4(7)
Cisco Nexus 3000 Series Switches - addressed in versions 9.3(11), 10.3(2)
Cisco Nexus 9000 Series Switches NX-OS Mode - addressed in versions 9.3(11), 10.3(2)
PowerFlex Appliance - update to IC 38.363.02
PowerFlex rack - update to 3.6.3.2
Connectrix Cisco MDS 9000 - addressed in versions 8.4(2f), 9.3(2)

External References

Related Security Bulletins