Description
A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to perform a directory traversal and access resources that are outside the filesystem mountpoint of the web UI. This vulnerability is due to an insufficient security configuration. An attacker could exploit this vulnerability by sending a crafted request to the web UI. A successful exploit could allow the attacker to gain read access to files that are outside the filesystem mountpoint of the web UI. Note: These files are located on a restricted filesystem that is maintained for the web UI. There is no ability to write to any files on this filesystem.
Published: 2023-03-23
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-24245 A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to perform a directory traversal and access resources that are outside the filesystem mountpoint of the web UI. This vulnerability is due to an insufficient security configuration. An attacker could exploit this vulnerability by sending a crafted request to the web UI. A successful exploit could allow the attacker to gain read access to files that are outside the filesystem mountpoint of the web UI. Note: These files are located on a restricted filesystem that is maintained for the web UI. There is no ability to write to any files on this filesystem.
History

Fri, 25 Oct 2024 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Cisco 1000 Integrated Services Router 1100-4g Integrated Services Router 1100-4p Integrated Services Router 1100-6g Integrated Services Router 1100-8p Integrated Services Router 1100 Integrated Services Router 1101-4p Integrated Services Router 1101 Integrated Services Router 1109-2p Integrated Services Router 1109-4p Integrated Services Router 1109 Integrated Services Router 1111x-8p Integrated Services Router 1111x Integrated Services Router 111x Integrated Services Router 1120 Integrated Services Router 1131 Integrated Services Router 1160 Integrated Services Router 4000 Integrated Services Router 4221 Integrated Services Router 4321 Integrated Services Router 4331 Integrated Services Router 4351 Integrated Services Router 4431 Integrated Services Router 4451-x Integrated Services Router 4451 Integrated Services Router 4461 Integrated Services Router 8101-32fh 8101-32h 8102-64h 8201 8201-32fh 8202 8800 12-slot 8800 18-slot 8800 4-slot 8800 8-slot 8804 8808 8812 8818 8831 9800-40 9800-80 9800-cl 9800-l Asr 1000 Asr 1000-esp100 Asr 1000-esp100-x Asr 1000-esp200-x Asr 1001 Asr 1001-hx Asr 1001-hx R Asr 1001-x Asr 1001-x R Asr 1002 Asr 1002-hx Asr 1002-hx R Asr 1002-x Asr 1002-x R Asr 1004 Asr 1006 Asr 1006-x Asr 1009-x Asr 1013 Asr 1023 Asr 900 Asr 9000 Asr 9000v Asr 9001 Asr 9006 Asr 901-12c-f-d Asr 901-12c-ft-d Asr 901-4c-f-d Asr 901-4c-ft-d Asr 901-6cz-f-a Asr 901-6cz-f-d Asr 901-6cz-fs-a Asr 901-6cz-fs-d Asr 901-6cz-ft-a Asr 901-6cz-ft-d Asr 9010 Asr 901s-2sg-f-ah Asr 901s-2sg-f-d Asr 901s-3sg-f-ah Asr 901s-3sg-f-d Asr 901s-4sg-f-d Asr 902 Asr 902u Asr 903 Asr 907 Asr 914 Asr 920-10sz-pd Asr 920-10sz-pd R Asr 920-12cz-a Asr 920-12cz-a R Asr 920-12cz-d Asr 920-12cz-d R Asr 920-12sz-im Asr 920-12sz-im R Asr 920-24sz-im Asr 920-24sz-im R Asr 920-24sz-m Asr 920-24sz-m R Asr 920-24tz-m Asr 920-24tz-m R Asr 920-4sz-a Asr 920-4sz-a R Asr 920-4sz-d Asr 920-4sz-d R Asr 920u-12sz-im Asr 9901 Asr 9902 Asr 9903 Asr 9904 Asr 9906 Asr 9910 Asr 9912 Asr 9920 Asr 9922 Catalyst 3850 Catalyst 3850-12s-e Catalyst 3850-12s-s Catalyst 3850-12x48u Catalyst 3850-12xs-e Catalyst 3850-12xs-s Catalyst 3850-16xs-e Catalyst 3850-16xs-s Catalyst 3850-24p-e Catalyst 3850-24p-l Catalyst 3850-24p-s Catalyst 3850-24pw-s Catalyst 3850-24s-e Catalyst 3850-24s-s Catalyst 3850-24t-e Catalyst 3850-24t-l Catalyst 3850-24t-s Catalyst 3850-24u Catalyst 3850-24u-e Catalyst 3850-24u-l Catalyst 3850-24u-s Catalyst 3850-24xs Catalyst 3850-24xs-e Catalyst 3850-24xs-s Catalyst 3850-24xu Catalyst 3850-24xu-e Catalyst 3850-24xu-l Catalyst 3850-24xu-s Catalyst 3850-32xs-e Catalyst 3850-32xs-s Catalyst 3850-48f-e Catalyst 3850-48f-l Catalyst 3850-48f-s Catalyst 3850-48p-e Catalyst 3850-48p-l Catalyst 3850-48p-s Catalyst 3850-48pw-s Catalyst 3850-48t-e Catalyst 3850-48t-l Catalyst 3850-48t-s Catalyst 3850-48u Catalyst 3850-48u-e Catalyst 3850-48u-l Catalyst 3850-48u-s Catalyst 3850-48xs Catalyst 3850-48xs-e Catalyst 3850-48xs-f-e Catalyst 3850-48xs-f-s Catalyst 3850-48xs-s Catalyst 3850-nm-2-40g Catalyst 3850-nm-8-10g Catalyst 8200 Catalyst 8300 Catalyst 8300-1n1s-4t2x Catalyst 8300-1n1s-6t Catalyst 8300-2n2s-4t2x Catalyst 8300-2n2s-6t Catalyst 8500 Catalyst 8500-4qc Catalyst 8500l Catalyst 8510csr Catalyst 8510msr Catalyst 8540csr Catalyst 8540msr Catalyst 9200 Catalyst 9200cx Catalyst 9200l Catalyst 9300 Catalyst 9300-24p-a Catalyst 9300-24p-e Catalyst 9300-24s-a Catalyst 9300-24s-e Catalyst 9300-24t-a Catalyst 9300-24t-e Catalyst 9300-24u-a Catalyst 9300-24u-e Catalyst 9300-24ux-a Catalyst 9300-24ux-e Catalyst 9300-48p-a Catalyst 9300-48p-e Catalyst 9300-48s-a Catalyst 9300-48s-e Catalyst 9300-48t-a Catalyst 9300-48t-e Catalyst 9300-48u-a Catalyst 9300-48u-e Catalyst 9300-48un-a Catalyst 9300-48un-e Catalyst 9300-48uxm-a Catalyst 9300-48uxm-e Catalyst 9300l Catalyst 9300l-24p-4g-a Catalyst 9300l-24p-4g-e Catalyst 9300l-24p-4x-a Catalyst 9300l-24p-4x-e Catalyst 9300l-24t-4g-a Catalyst 9300l-24t-4g-e Catalyst 9300l-24t-4x-a Catalyst 9300l-24t-4x-e Catalyst 9300l-48p-4g-a Catalyst 9300l-48p-4g-e Catalyst 9300l-48p-4x-a Catalyst 9300l-48p-4x-e Catalyst 9300l-48t-4g-a Catalyst 9300l-48t-4g-e Catalyst 9300l-48t-4x-a Catalyst 9300l-48t-4x-e Catalyst 9300l Stack Catalyst 9300lm Catalyst 9300x Catalyst 9400 Catalyst 9400 Supervisor Engine-1 Catalyst 9407r Catalyst 9410r Catalyst 9500 Catalyst 9500h Catalyst 9600 Catalyst 9600 Supervisor Engine-1 Catalyst 9600x Catalyst 9800 Catalyst 9800-40 Catalyst 9800-40 Wireless Controller Catalyst 9800-80 Catalyst 9800-80 Wireless Controller Catalyst 9800-cl Catalyst 9800-l Catalyst 9800-l-c Catalyst 9800-l-f Catalyst 9800 Embedded Wireless Controller Catalyst Ie3200 Catalyst Ie3200 Rugged Switch Catalyst Ie3300 Catalyst Ie3300 Rugged Switch Catalyst Ie3400 Catalyst Ie3400 Heavy Duty Switch Catalyst Ie3400 Rugged Switch Catalyst Ie9300 Cbr-8 Cg418-e Cg522-e Esr6300 Ess-3300-24t-con-a Ess-3300-24t-con-e Ess-3300-24t-ncp-a Ess-3300-24t-ncp-e Ess-3300-con-a Ess-3300-con-e Ess-3300-ncp-a Ess-3300-ncp-e Ess9300-10x-e Integrated Services Virtual Router Ios Xe
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2024-10-25T16:02:41.984Z

Reserved: 2022-10-27T00:00:00.000Z

Link: CVE-2023-20066

cve-icon Vulnrichment

Updated: 2024-08-02T08:57:35.555Z

cve-icon NVD

Status : Modified

Published: 2023-03-23T17:15:14.547

Modified: 2024-11-21T07:40:28.413

Link: CVE-2023-20066

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses