A vulnerability in Cisco Intersight Virtual Appliance could allow an unauthenticated, adjacent attacker to access internal HTTP services that are otherwise inaccessible.
This vulnerability is due to insufficient restrictions on internally accessible http proxies. An attacker could exploit this vulnerability by submitting a crafted CLI command. A successful exploit could allow the attacker access to internal subnets beyond the sphere of their intended access level.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: cisco
Published: 2023-08-16T21:00:25.948Z
Updated: 2024-08-02T09:05:35.989Z
Reserved: 2022-10-27T18:47:50.370Z
Link: CVE-2023-20237
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-08-16T22:15:12.777
Modified: 2024-11-21T07:40:57.847
Link: CVE-2023-20237
Redhat
No data.