← Vulnerability feed

Vulnerability record · CVE-2023-20015 · published 23 February 2023

CVE-2023-20015: Cisco ucs central software os command injection vulnerability

Cisco · Ucs Central Software

A vulnerability in the CLI of Cisco Firepower 4100 Series, Cisco Firepower 9300 Security Appliances, and Cisco UCS 6200, 6300, 6400, and 6500 Series Fabric Interconnects could allow an authenticated, local attacker to inject unauthorized commands. This vulnerability is due to insufficient input validation of commands supplied by the user. An attacker could exploit this vulnerability by authenticating to a device and submitting crafted input to the affected command. A successful exploit could allow the attacker to execute unauthorized commands within the CLI. An attacker with Administrator privileges could also execute arbitrary commands on the underlying operating system of Cisco UCS 6400 and 6500 Series Fabric Interconnects with root-level privileges.

6.7 CVSS 3.1 Medium EPSS 0.22% · top 88.3% CWE-78 · OS command injection
6.7CVSS 3.1 base score
0.22%EPSS exploitation probability, 30 days
NoNot in CISA KEV
12Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the CLI of Cisco Firepower 4100 Series, Cisco Firepower 9300 Security Appliances, and Cisco UCS 6200, 6300, 6400, and 6500 Series Fabric Interconnects could allow an authenticated, local attacker to inject unauthorized commands. This vulnerability is due to insufficient input validation of commands supplied by the user. An attacker could exploit this vulnerability by authenticating to a device and submitting crafted input to the affected command. A successful exploit could allow the attacker to execute unauthorized commands within the CLI. An attacker with Administrator privileges could also execute arbitrary commands on the underlying operating system of Cisco UCS 6400 and 6500 Series Fabric Interconnects with root-level privileges.

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected products

12 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-20015 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-0310Cisco nx-os out-of-bounds read vulnerabilityA vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacke…EPSS 4.1%9.8CVE-2015-6435Cisco firepower extensible operating system os command injection vulnerabilityAn unspecified CGI script in Cisco FX-OS before 1.1.2 on Firepower 9000 devices and Cisco Unified Computing System (UCS) Manager before 2.2(4b), 2.2(…EPSS 8.7%8.8CVE-2021-1368Cisco nx-os out-of-bounds write vulnerabilityA vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, a…EPSS 0.46%8.8CVE-2020-3456Cisco firepower extensible operating system cross-site request forgery vulnerabilityA vulnerability in the Cisco Firepower Chassis Manager (FCM) of Cisco FXOS Software could allow an unauthenticated, remote attacker to conduct a cros…EPSS 0.56%8.8CVE-2020-3172Cisco firepower extensible operating system improper input validation vulnerabilityA vulnerability in the Cisco Discovery Protocol feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent atta…EPSS 1.9%8.8CVE-2018-0303Cisco nx-os improper input validation vulnerabilityA vulnerability in the Cisco Discovery Protocol component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent at…EPSS 1.1%8.8CVE-2017-12277Cisco firepower extensible operating system improper input validation vulnerabilityA vulnerability in the Smart Licensing Manager service of the Cisco Firepower 4100 Series Next-Generation Firewall (NGFW) and Firepower 9300 Security…EPSS 3.8%8.6CVE-2020-3517Cisco firepower extensible operating system null pointer dereference vulnerabilityA vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated attacker to cau…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2023-20015), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.