CVE-2023-20168: Input Validation
A vulnerability in TACACS+ and RADIUS remote authentication for Cisco NX-OS Software could allow an unauthenticated, local attacker to cause an affected device to unexpectedly reload. This vulnerability is due to incorrect input validation when processing an authentication attempt if the directed request option is enabled for TACACS+ or RADIUS. An attacker could exploit this vulnerability by entering a crafted string at the login prompt of an affected device. A successful exploit could allow the attacker to cause the affected device to unexpectedly reload, resulting in a denial of service (DoS) condition.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-20168?
CVE-2023-20168 is rated as high severity due to its potential to allow an unauthenticated local attacker to cause a device reload.
How do I fix CVE-2023-20168?
To fix CVE-2023-20168, upgrade to the recommended fixed versions of Cisco NX-OS, specifically versions 9.3(11) or 10.2(5).
Who is affected by CVE-2023-20168?
CVE-2023-20168 affects devices running vulnerable Cisco NX-OS Software versions including 9.3(11) and 10.2(5).
What impact does CVE-2023-20168 have?
CVE-2023-20168 can lead to a denial of service by causing a device to unexpectedly reload.
Is there a workaround for CVE-2023-20168?
Currently, there are no known workarounds for CVE-2023-20168; applying the software updates is recommended.