Description
A vulnerability in the CLI console login authentication of Cisco Nexus 9300-FX3 Series Fabric Extender (FEX) when used in UCS Fabric Interconnect deployments could allow an unauthenticated attacker with physical access to bypass authentication. This vulnerability is due to the improper implementation of the password validation function. An attacker could exploit this vulnerability by logging in to the console port on an affected device. A successful exploit could allow the attacker to bypass authentication and execute a limited set of commands local to the FEX, which could cause a device reboot and denial of service (DoS) condition.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-24191 | A vulnerability in the CLI console login authentication of Cisco Nexus 9300-FX3 Series Fabric Extender (FEX) when used in UCS Fabric Interconnect deployments could allow an unauthenticated attacker with physical access to bypass authentication. This vulnerability is due to the improper implementation of the password validation function. An attacker could exploit this vulnerability by logging in to the console port on an affected device. A successful exploit could allow the attacker to bypass authentication and execute a limited set of commands local to the FEX, which could cause a device reboot and denial of service (DoS) condition. |
References
History
Fri, 25 Oct 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Subscriptions
Cisco
Subscribe
Nexus 93180yc-fx3
Subscribe
Nexus 93180yc-fx3 Firmware
Subscribe
Nexus 93180yc-fx3s
Subscribe
Nexus 93180yc-fx3s Firmware
Subscribe
Ucs 64108
Subscribe
Ucs 64108 Firmware
Subscribe
Ucs 6454
Subscribe
Ucs 6454 Firmware
Subscribe
Ucs 6536
Subscribe
Ucs 6536 Firmware
Subscribe
Ucs Central Software
Subscribe
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-10-25T16:04:09.781Z
Reserved: 2022-10-27T00:00:00.000Z
Link: CVE-2023-20012
Updated: 2024-08-02T08:57:35.036Z
Status : Modified
Published: 2023-02-23T20:15:13.247
Modified: 2024-11-21T07:40:20.440
Link: CVE-2023-20012
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD