CVE-2023-20017

CVSS 3.1 Score 9.1 of 10 (high)

Details

Published Aug 16, 2023
Updated: Jan 25, 2024
CWE ID 78
CWE ID 77

Summary

CVE-2023-20017 refers to multiple vulnerabilities in Cisco Intersight Private Virtual Appliance. An authenticated, remote attacker with Administrator privileges can exploit these weaknesses by uploading crafted software packages. Insufficient input validation is the root cause, leading to the execution of arbitrary commands with root-level privileges on the underlying operating system. This can potentially compromise the affected device. Organizations using Cisco Intersight Private Virtual Appliance are advised to apply the available patches to mitigate these risks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share