CVE-2023-20234

A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to create a file or overwrite any file on the filesystem of an affected device, including system files. The vulnerability occurs because there is no validation of parameters when a specific CLI command is used. An attacker could exploit this vulnerability by authenticating to an affected device and using the command at the CLI. A successful exploit could allow the attacker to overwrite any file on the disk of the affected device, including system files. The attacker must have valid administrative credentials on the affected device to exploit this vulnerability.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:cisco:firepower_extensible_operating_system:-:*:*:*:*:*:*:*
OR cpe:2.3:h:cisco:firepower_1000:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_1010:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_1020:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_1030:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_1040:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_2100:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_2110:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_2120:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_2130:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_2140:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_4100:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_4110:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_4110_next-generation_firewall:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_4112:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_4115:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_4120:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_4120_next-generation_firewall:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_4125:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_4140:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_4140_next-generation_firewall:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_4145:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_4150:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_4150_next-generation_firewall:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_9300:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_9300_security_appliance:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_9300_sm-24:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_9300_sm-36:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_9300_sm-40:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_9300_sm-44:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_9300_sm-44_x_3:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_9300_sm-48:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_9300_sm-56:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_9300_sm-56_x_3:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_9300_with_1_sm-24_module:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_9300_with_1_sm-36_module:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_9300_with_1_sm-44_module:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:firepower_9300_with_3_sm-44_module:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:secure_firewall_3105:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:secure_firewall_3110:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:secure_firewall_3120:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:secure_firewall_3130:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:secure_firewall_3140:-:*:*:*:*:*:*:*

History

21 Nov 2024, 07:40

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 6.0
v2 : unknown
v3 : 4.4
References () https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fxos-arbitrary-file-BLk6YupL - Vendor Advisory () https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fxos-arbitrary-file-BLk6YupL - Vendor Advisory

25 Jan 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-23 19:15

Updated : 2024-11-21 07:40


NVD link : CVE-2023-20234

Mitre link : CVE-2023-20234

CVE.ORG link : CVE-2023-20234


JSON object : View

Products Affected

cisco

  • secure_firewall_3105
  • firepower_9300_with_1_sm-36_module
  • firepower_4145
  • firepower_4115
  • firepower_9300_sm-44_x_3
  • firepower_1000
  • firepower_4110
  • firepower_4140
  • firepower_1010
  • firepower_9300
  • firepower_2120
  • firepower_2100
  • firepower_4125
  • firepower_9300_sm-44
  • firepower_9300_security_appliance
  • firepower_2130
  • firepower_4120_next-generation_firewall
  • firepower_9300_sm-48
  • firepower_1020
  • firepower_9300_sm-56_x_3
  • firepower_1030
  • firepower_4112
  • firepower_9300_with_1_sm-24_module
  • firepower_4150_next-generation_firewall
  • firepower_4140_next-generation_firewall
  • firepower_extensible_operating_system
  • firepower_9300_with_1_sm-44_module
  • secure_firewall_3120
  • firepower_2140
  • firepower_4110_next-generation_firewall
  • firepower_9300_sm-36
  • secure_firewall_3130
  • firepower_4120
  • firepower_4150
  • firepower_1040
  • firepower_9300_sm-56
  • firepower_9300_sm-24
  • firepower_2110
  • firepower_9300_with_3_sm-44_module
  • secure_firewall_3110
  • secure_firewall_3140
  • firepower_4100
  • firepower_9300_sm-40
CWE
CWE-73

External Control of File Name or Path

CWE-732

Incorrect Permission Assignment for Critical Resource