CVE-2023-20168
Summary
| CVE | CVE-2023-20168 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-08-23 19:15:00 UTC |
| Updated | 2024-01-25 17:15:00 UTC |
| Description | A vulnerability in TACACS+ and RADIUS remote authentication for Cisco NX-OS Software could allow an unauthenticated, local attacker to cause an affected device to unexpectedly reload. This vulnerability is due to incorrect input validation when processing an authentication attempt if the directed request option is enabled for TACACS+ or RADIUS. An attacker could exploit this vulnerability by entering a crafted string at the login prompt of an affected device. A successful exploit could allow the attacker to cause the affected device to unexpectedly reload, resulting in a denial of service (DoS) condition. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Cisco | Mds 9000 | - | All | All | All |
| Hardware | Cisco | Mds 9100 | - | All | All | All |
| Hardware | Cisco | Mds 9132t | - | All | All | All |
| Hardware | Cisco | Mds 9134 | - | All | All | All |
| Hardware | Cisco | Mds 9140 | - | All | All | All |
| Hardware | Cisco | Mds 9148 | - | All | All | All |
| Hardware | Cisco | Mds 9148s | - | All | All | All |
| Hardware | Cisco | Mds 9148t | - | All | All | All |
| Hardware | Cisco | Mds 9200 | - | All | All | All |
| Hardware | Cisco | Mds 9216 | - | All | All | All |
| Hardware | Cisco | Mds 9216a | - | All | All | All |
| Hardware | Cisco | Mds 9216i | - | All | All | All |
| Hardware | Cisco | Mds 9222i | - | All | All | All |
| Hardware | Cisco | Mds 9250i | - | All | All | All |
| Hardware | Cisco | Mds 9396s | - | All | All | All |
| Hardware | Cisco | Mds 9396t | - | All | All | All |
| Hardware | Cisco | Mds 9500 | - | All | All | All |
| Hardware | Cisco | Mds 9506 | - | All | All | All |
| Hardware | Cisco | Mds 9509 | - | All | All | All |
| Hardware | Cisco | Mds 9513 | - | All | All | All |
| Hardware | Cisco | Mds 9700 | - | All | All | All |
| Hardware | Cisco | Mds 9706 | - | All | All | All |
| Hardware | Cisco | Mds 9710 | - | All | All | All |
| Hardware | Cisco | Mds 9718 | - | All | All | All |
| Hardware | Cisco | Nexus 1000v | - | All | All | All |
| Hardware | Cisco | Nexus 1000v | - | All | All | All |
| Hardware | Cisco | Nexus 1000 Virtual Edge | - | All | All | All |
| Hardware | Cisco | Nexus 3048 | - | All | All | All |
| Hardware | Cisco | Nexus 31108pc-v | - | All | All | All |
| Hardware | Cisco | Nexus 31108tc-v | - | All | All | All |
| Hardware | Cisco | Nexus 31128pq | - | All | All | All |
| Hardware | Cisco | Nexus 3132c-z | - | All | All | All |
| Hardware | Cisco | Nexus 3132q-v | - | All | All | All |
| Hardware | Cisco | Nexus 3132q-xl | - | All | All | All |
| Hardware | Cisco | Nexus 3164q | - | All | All | All |
| Hardware | Cisco | Nexus 3172pq | - | All | All | All |
| Hardware | Cisco | Nexus 3172pq-xl | - | All | All | All |
| Hardware | Cisco | Nexus 3172tq | - | All | All | All |
| Hardware | Cisco | Nexus 3172tq-32t | - | All | All | All |
| Hardware | Cisco | Nexus 3172tq-xl | - | All | All | All |
| Hardware | Cisco | Nexus 3232 | - | All | All | All |
| Hardware | Cisco | Nexus 3264c-e | - | All | All | All |
| Hardware | Cisco | Nexus 3264q | - | All | All | All |
| Hardware | Cisco | Nexus 3408-s | - | All | All | All |
| Hardware | Cisco | Nexus 34180yc | - | All | All | All |
| Hardware | Cisco | Nexus 34200yc-sm | - | All | All | All |
| Hardware | Cisco | Nexus 3432d-s | - | All | All | All |
| Hardware | Cisco | Nexus 3464c | - | All | All | All |
| Hardware | Cisco | Nexus 3524 | - | All | All | All |
| Hardware | Cisco | Nexus 3524-x | - | All | All | All |
| Hardware | Cisco | Nexus 3524-xl | - | All | All | All |
| Hardware | Cisco | Nexus 3548 | - | All | All | All |
| Hardware | Cisco | Nexus 3548-x | - | All | All | All |
| Hardware | Cisco | Nexus 3548-xl | - | All | All | All |
| Hardware | Cisco | Nexus 36180yc-r | - | All | All | All |
| Hardware | Cisco | Nexus 5500 | - | All | All | All |
| Hardware | Cisco | Nexus 5548p | - | All | All | All |
| Hardware | Cisco | Nexus 5548up | - | All | All | All |
| Hardware | Cisco | Nexus 5596t | - | All | All | All |
| Hardware | Cisco | Nexus 5596up | - | All | All | All |
| Hardware | Cisco | Nexus 5600 | - | All | All | All |
| Hardware | Cisco | Nexus 56128p | - | All | All | All |
| Hardware | Cisco | Nexus 5624q | - | All | All | All |
| Hardware | Cisco | Nexus 5648q | - | All | All | All |
| Hardware | Cisco | Nexus 5672up | - | All | All | All |
| Hardware | Cisco | Nexus 5672up-16g | - | All | All | All |
| Hardware | Cisco | Nexus 5696q | - | All | All | All |
| Hardware | Cisco | Nexus 6000 | - | All | All | All |
| Hardware | Cisco | Nexus 6001 | - | All | All | All |
| Hardware | Cisco | Nexus 6001p | - | All | All | All |
| Hardware | Cisco | Nexus 6001t | - | All | All | All |
| Hardware | Cisco | Nexus 6004 | - | All | All | All |
| Hardware | Cisco | Nexus 6004x | - | All | All | All |
| Hardware | Cisco | Nexus 7000 | - | All | All | All |
| Hardware | Cisco | Nexus 7004 | - | All | All | All |
| Hardware | Cisco | Nexus 7009 | - | All | All | All |
| Hardware | Cisco | Nexus 7010 | - | All | All | All |
| Hardware | Cisco | Nexus 7018 | - | All | All | All |
| Hardware | Cisco | Nexus 9232e | - | All | All | All |
| Hardware | Cisco | Nexus 92348gc-x | - | All | All | All |
| Hardware | Cisco | Nexus 9408 | - | All | All | All |
| Hardware | Cisco | Nexus 9504 | - | All | All | All |
| Hardware | Cisco | Nexus 9508 | - | All | All | All |
| Hardware | Cisco | Nexus 9516 | - | All | All | All |
| Operating System | Cisco | Nx-os | - | All | All | All |
| Operating System | Cisco | Nx-os | 10.2\(5\) | All | All | All |
| Operating System | Cisco | Nx-os | 9.3\(11\) | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco NX-OS Software TACACS+ or RADIUS Remote Authentication Directed Request Denial of Service Vulnerability | MISC | sec.cloudapps.cisco.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.