VDB
CVE-2023-20237
CVE-2023-20237
PUBLISHED
CVSS 4.300000190734863 MEDIUM
A vulnerability in Cisco Intersight Virtual Appliance could allow an unauthenticated, adjacent attacker to access internal HTTP services that are otherwise inaccessible. This vulnerability is due to insufficient restrictions on internally accessible http proxies. An attacker could exploit this vulnerability by submitting a crafted CLI command. A successful exploit could allow the attacker access to internal subnets beyond the sphere of their intended access level.
EPSS 0.27% · 18.5th percentile
Risk Scores
CVSS 3.1
4.300000190734863
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS Score
0.27%
18.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Cisco Intersight Virtual Appliance | 1.0.9-503, 1.0.9-536, 1.0.9-538 |
| cisco | intersight_virtual_appliance | 0 |
Timeline
- Aug 16, 2023 CVE Published
- Aug 18, 2023 EPSS Score
- Sep 20, 2023 EPSS Score
- Oct 24, 2023 EPSS Score
- Nov 26, 2023 EPSS Score
- Dec 30, 2023 EPSS Score
- Feb 1, 2024 EPSS Score
- Mar 5, 2024 EPSS Score
- Apr 8, 2024 EPSS Score
- May 11, 2024 EPSS Score
- Jun 14, 2024 EPSS Score
- Jul 17, 2024 EPSS Score