CVE-2023-20115
Summary
| CVE | CVE-2023-20115 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-08-23 19:15:00 UTC |
| Updated | 2024-01-25 17:15:00 UTC |
| Description | A vulnerability in the SFTP server implementation for Cisco Nexus 3000 Series Switches and 9000 Series Switches in standalone NX-OS mode could allow an authenticated, remote attacker to download or overwrite files from the underlying operating system of an affected device. This vulnerability is due to a logic error when verifying the user role when an SFTP connection is opened to an affected device. An attacker could exploit this vulnerability by connecting and authenticating via SFTP as a valid, non-administrator user. A successful exploit could allow the attacker to read or overwrite files from the underlying operating system with the privileges of the authenticated user. There are workarounds that address this vulnerability. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Cisco | Nexus 3048 | - | All | All | All |
| Hardware | Cisco | Nexus 31108pc-v | - | All | All | All |
| Hardware | Cisco | Nexus 31108tc-v | - | All | All | All |
| Hardware | Cisco | Nexus 31128pq | - | All | All | All |
| Hardware | Cisco | Nexus 3132c-z | - | All | All | All |
| Hardware | Cisco | Nexus 3132q-v | - | All | All | All |
| Hardware | Cisco | Nexus 3132q-xl | - | All | All | All |
| Hardware | Cisco | Nexus 3164q | - | All | All | All |
| Hardware | Cisco | Nexus 3172pq | - | All | All | All |
| Hardware | Cisco | Nexus 3172pq-xl | - | All | All | All |
| Hardware | Cisco | Nexus 3172tq | - | All | All | All |
| Hardware | Cisco | Nexus 3172tq-32t | - | All | All | All |
| Hardware | Cisco | Nexus 3172tq-xl | - | All | All | All |
| Hardware | Cisco | Nexus 3232c | - | All | All | All |
| Hardware | Cisco | Nexus 3264c-e | - | All | All | All |
| Hardware | Cisco | Nexus 3264q | - | All | All | All |
| Hardware | Cisco | Nexus 3408-s | - | All | All | All |
| Hardware | Cisco | Nexus 34180yc | - | All | All | All |
| Hardware | Cisco | Nexus 34200yc-sm | - | All | All | All |
| Hardware | Cisco | Nexus 3432d-s | - | All | All | All |
| Hardware | Cisco | Nexus 3464c | - | All | All | All |
| Hardware | Cisco | Nexus 3524 | - | All | All | All |
| Hardware | Cisco | Nexus 3524-x | - | All | All | All |
| Hardware | Cisco | Nexus 3524-xl | - | All | All | All |
| Hardware | Cisco | Nexus 3548 | - | All | All | All |
| Hardware | Cisco | Nexus 3548-x | - | All | All | All |
| Hardware | Cisco | Nexus 3548-xl | - | All | All | All |
| Hardware | Cisco | Nexus 36180yc-r | - | All | All | All |
| Hardware | Cisco | Nexus 3636c-r | - | All | All | All |
| Hardware | Cisco | Nexus 9000v | - | All | All | All |
| Hardware | Cisco | Nexus 92160yc-x | - | All | All | All |
| Hardware | Cisco | Nexus 92300yc | - | All | All | All |
| Hardware | Cisco | Nexus 92304qc | - | All | All | All |
| Hardware | Cisco | Nexus 9232e | - | All | All | All |
| Hardware | Cisco | Nexus 92348gc-x | - | All | All | All |
| Hardware | Cisco | Nexus 9236c | - | All | All | All |
| Hardware | Cisco | Nexus 9272q | - | All | All | All |
| Hardware | Cisco | Nexus 93108tc-ex | - | All | All | All |
| Hardware | Cisco | Nexus 93108tc-ex-24 | - | All | All | All |
| Hardware | Cisco | Nexus 93108tc-fx | - | All | All | All |
| Hardware | Cisco | Nexus 93108tc-fx-24 | - | All | All | All |
| Hardware | Cisco | Nexus 93108tc-fx3h | - | All | All | All |
| Hardware | Cisco | Nexus 93108tc-fx3p | - | All | All | All |
| Hardware | Cisco | Nexus 93120tx | - | All | All | All |
| Hardware | Cisco | Nexus 93128tx | - | All | All | All |
| Hardware | Cisco | Nexus 9316d-gx | - | All | All | All |
| Hardware | Cisco | Nexus 93180lc-ex | - | All | All | All |
| Hardware | Cisco | Nexus 93180yc-ex | - | All | All | All |
| Hardware | Cisco | Nexus 93180yc-ex-24 | - | All | All | All |
| Hardware | Cisco | Nexus 93180yc-fx | - | All | All | All |
| Hardware | Cisco | Nexus 93180yc-fx-24 | - | All | All | All |
| Hardware | Cisco | Nexus 93180yc-fx3 | - | All | All | All |
| Hardware | Cisco | Nexus 93180yc-fx3h | - | All | All | All |
| Hardware | Cisco | Nexus 93180yc-fx3s | - | All | All | All |
| Hardware | Cisco | Nexus 93216tc-fx2 | - | All | All | All |
| Hardware | Cisco | Nexus 93240yc-fx2 | - | All | All | All |
| Hardware | Cisco | Nexus 9332c | - | All | All | All |
| Hardware | Cisco | Nexus 9332d-gx2b | - | All | All | All |
| Hardware | Cisco | Nexus 9332d-h2r | - | All | All | All |
| Hardware | Cisco | Nexus 9332pq | - | All | All | All |
| Hardware | Cisco | Nexus 93360yc-fx2 | - | All | All | All |
| Hardware | Cisco | Nexus 9336c-fx2 | - | All | All | All |
| Hardware | Cisco | Nexus 9336c-fx2-e | - | All | All | All |
| Hardware | Cisco | Nexus 9336pq Aci Spine | - | All | All | All |
| Hardware | Cisco | Nexus 9348d-gx2a | - | All | All | All |
| Hardware | Cisco | Nexus 9348gc-fx3 | - | All | All | All |
| Hardware | Cisco | Nexus 9348gc-fxp | - | All | All | All |
| Hardware | Cisco | Nexus 93600cd-gx | - | All | All | All |
| Hardware | Cisco | Nexus 9364c | - | All | All | All |
| Hardware | Cisco | Nexus 9364c-gx | - | All | All | All |
| Hardware | Cisco | Nexus 9364d-gx2a | - | All | All | All |
| Hardware | Cisco | Nexus 9372px | - | All | All | All |
| Hardware | Cisco | Nexus 9372px-e | - | All | All | All |
| Hardware | Cisco | Nexus 9372tx | - | All | All | All |
| Hardware | Cisco | Nexus 9372tx-e | - | All | All | All |
| Hardware | Cisco | Nexus 9396px | - | All | All | All |
| Hardware | Cisco | Nexus 9396tx | - | All | All | All |
| Hardware | Cisco | Nexus 9408 | - | All | All | All |
| Hardware | Cisco | Nexus 9508 | - | All | All | All |
| Hardware | Cisco | Nexus 9804 | - | All | All | All |
| Hardware | Cisco | Nexus 9808 | - | All | All | All |
| Operating System | Cisco | Nx-os | 10.1\(1\) | All | All | All |
| Operating System | Cisco | Nx-os | 10.1\(2t\) | All | All | All |
| Operating System | Cisco | Nx-os | 10.1\(2\) | All | All | All |
| Operating System | Cisco | Nx-os | 10.2\(1q\) | All | All | All |
| Operating System | Cisco | Nx-os | 10.2\(1\) | All | All | All |
| Operating System | Cisco | Nx-os | 10.2\(2\) | All | All | All |
| Operating System | Cisco | Nx-os | 10.2\(3t\) | All | All | All |
| Operating System | Cisco | Nx-os | 10.2\(3\) | All | All | All |
| Operating System | Cisco | Nx-os | 10.2\(4\) | All | All | All |
| Operating System | Cisco | Nx-os | 10.2\(5\) | All | All | All |
| Operating System | Cisco | Nx-os | 10.3\(1\) | All | All | All |
| Operating System | Cisco | Nx-os | 10.3\(2\) | All | All | All |
| Operating System | Cisco | Nx-os | 9.2\(1\) | All | All | All |
| Operating System | Cisco | Nx-os | 9.2\(2t\) | All | All | All |
| Operating System | Cisco | Nx-os | 9.2\(2v\) | All | All | All |
| Operating System | Cisco | Nx-os | 9.2\(2\) | All | All | All |
| Operating System | Cisco | Nx-os | 9.2\(3\) | All | All | All |
| Operating System | Cisco | Nx-os | 9.2\(4\) | All | All | All |
| Operating System | Cisco | Nx-os | 9.3\(10\) | All | All | All |
| Operating System | Cisco | Nx-os | 9.3\(11\) | All | All | All |
| Operating System | Cisco | Nx-os | 9.3\(1\) | All | All | All |
| Operating System | Cisco | Nx-os | 9.3\(2\) | All | All | All |
| Operating System | Cisco | Nx-os | 9.3\(3\) | All | All | All |
| Operating System | Cisco | Nx-os | 9.3\(4\) | All | All | All |
| Operating System | Cisco | Nx-os | 9.3\(5\) | All | All | All |
| Operating System | Cisco | Nx-os | 9.3\(6\) | All | All | All |
| Operating System | Cisco | Nx-os | 9.3\(7a\) | All | All | All |
| Operating System | Cisco | Nx-os | 9.3\(7\) | All | All | All |
| Operating System | Cisco | Nx-os | 9.3\(8\) | All | All | All |
| Operating System | Cisco | Nx-os | 9.3\(9\) | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco Nexus 3000 and 9000 Series Switches SFTP Server File Access Vulnerability | MISC | sec.cloudapps.cisco.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.