CVE-2023-20050: Cisco NX-OS Software CLI Command Injection Vulnerability
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of arguments that are passed to specific CLI commands. An attacker could exploit this vulnerability by including crafted input as the argument of an affected command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of the currently logged-in user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-20050?
CVE-2023-20050 has a severity rating of high due to its potential for enabling command execution by an authenticated, local attacker.
How do I fix CVE-2023-20050?
To remediate CVE-2023-20050, update Cisco NX-OS Software to the latest version that addresses the vulnerability.
Who is affected by CVE-2023-20050?
CVE-2023-20050 affects Cisco NX-OS Software deployed on various Cisco hardware platforms.
What are the risks associated with CVE-2023-20050?
Exploitation of CVE-2023-20050 could allow attackers to execute arbitrary commands on the underlying operating system, leading to potential system compromise.
Is CVE-2023-20050 being actively exploited in the wild?
As of the last update, there is no public indication that CVE-2023-20050 is being actively exploited, but organizations are urged to apply patches promptly.