CVE-2023-20263: Input Validation
A vulnerability in the web-based management interface of Cisco HyperFlex HX Data Platform could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of the parameters in an HTTP request. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to redirect a user to a malicious website.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2023-20263.
What is the severity of CVE-2023-20263?
The severity of CVE-2023-20263 is medium.
What is affected by CVE-2023-20263?
Cisco HyperFlex HX Data Platform versions 5.0 and 5.5 are affected by CVE-2023-20263.
How can an attacker exploit CVE-2023-20263?
An unauthenticated, remote attacker can exploit CVE-2023-20263 by redirecting a user to a malicious web page.
Is there a fix available for CVE-2023-20263?
Yes, Cisco has released a security advisory with mitigation information for CVE-2023-20263. Please refer to their advisory for more details.