CVE-2023-20012
A vulnerability in the CLI console login authentication of Cisco Nexus 9300-FX3 Series Fabric Extender (FEX) when used in UCS Fabric Interconnect deployments could allow an unauthenticated attacker with physical access to bypass authentication. This vulnerability is due to the improper implementation of the password validation function. An attacker could exploit this vulnerability by logging in to the console port on an affected device. A successful exploit could allow the attacker to bypass authentication and execute a limited set of commands local to the FEX, which could cause a device reboot and denial of service (DoS) condition.
Published:Feb 23, 2023
Last Modified:Nov 21, 2024
EPS:Feb 23, 2023
EPSS Score:0.00012
CVSS Score:5.3
Affected Products
Vendor
Product
Action
Vendor
Cisco
Product
Nexus 93180yc-fx3
Cisco
Nexus 93180yc-fx3
Vendor
Cisco
Product
Nexus 93180yc-fx3 Firmware
Cisco
Nexus 93180yc-fx3 Firmware
Vendor
Cisco
Product
Nexus 93180yc-fx3s
Cisco
Nexus 93180yc-fx3s
Vendor
Cisco
Product
Nexus 93180yc-fx3s Firmware
Cisco
Nexus 93180yc-fx3s Firmware
Vendor
Cisco
Product
Ucs 64108
Cisco
Ucs 64108
Vendor
Cisco
Product
Ucs 64108 Firmware
Cisco
Ucs 64108 Firmware
Vendor
Cisco
Product
Ucs 6454
Cisco
Ucs 6454
Vendor
Cisco
Product
Ucs 6454 Firmware
Cisco
Ucs 6454 Firmware
Vendor
Cisco
Product
Ucs 6536
Cisco
Ucs 6536
Vendor
Cisco
Product
Ucs 6536 Firmware
Cisco
Ucs 6536 Firmware
Vendor
Cisco
Product
Ucs Central Software
Cisco
Ucs Central Software
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
