CVE-2023-20237
MEDIUMCisco Intersight Virtual Appliance - Unauthenticated Access
Title source: llmDescription
A vulnerability in Cisco Intersight Virtual Appliance could allow an unauthenticated, adjacent attacker to access internal HTTP services that are otherwise inaccessible. This vulnerability is due to insufficient restrictions on internally accessible http proxies. An attacker could exploit this vulnerability by submitting a crafted CLI command. A successful exploit could allow the attacker access to internal subnets beyond the sphere of their intended access level.
References (1)
Core 1
Core References
Scores
CVSS v3
4.3
EPSS
0.0006
EPSS Percentile
17.6%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Details
CWE
CWE-284
CWE-77
Status
published
Products (1)
cisco/intersight_virtual_appliance
< 1.0.9-589
Published
Aug 16, 2023
Tracked Since
Feb 18, 2026