Security Advisory

CVE-2023-20103

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-04-05 00:00:00
Last updated 2024-10-25 16:01:32
Assigner cisco
State PUBLISHED

Description

A vulnerability in Cisco Secure Network Analytics could allow an authenticated, remote attacker to execute arbitrary code as a root user on an affected device. This vulnerability is due to insufficient validation of user input to the web interface. An attacker could exploit this vulnerability by uploading a crafted file to an affected device. A successful exploit could allow the attacker to execute code on the affected device. To exploit this vulnerability, an attacker would need to have valid Administrator credentials on the affected device.