← Vulnerability feed

Vulnerability record · CVE-2023-20016 · published 23 February 2023

CVE-2023-20016: Cisco ucs central software vulnerability

Cisco · Ucs Central Software

A vulnerability in the backup configuration feature of Cisco UCS Manager Software and in the configuration export feature of Cisco FXOS Software could allow an unauthenticated attacker with access to a backup file to decrypt sensitive information stored in the full state and configuration backup files. This vulnerability is due to a weakness in the encryption method used for the backup function. An attacker could exploit this vulnerability by leveraging a static key used for the backup configuration feature. A successful exploit could allow the attacker to decrypt sensitive information that is stored in full state and configuration backup files, such as local user credentials, authentication server passwords, Simple Network Management Protocol (SNMP) community names, and other credentials.

6.5 CVSS 3.1 Medium EPSS 0.11% · top 98.9% CWE-321 · CWE-321CWE-330 · CWE-330
6.5CVSS 3.1 base score
0.11%EPSS exploitation probability, 30 days
NoNot in CISA KEV
12Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the backup configuration feature of Cisco UCS Manager Software and in the configuration export feature of Cisco FXOS Software could allow an unauthenticated attacker with access to a backup file to decrypt sensitive information stored in the full state and configuration backup files. This vulnerability is due to a weakness in the encryption method used for the backup function. An attacker could exploit this vulnerability by leveraging a static key used for the backup configuration feature. A successful exploit could allow the attacker to decrypt sensitive information that is stored in full state and configuration backup files, such as local user credentials, authentication server passwords, Simple Network Management Protocol (SNMP) community names, and other credentials.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Affected products

12 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-20016 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed8.6CVE-2017-3883Cisco firepower extensible operating system allocation without limits vulnerabilityA vulnerability in the authentication, authorization, and accounting (AAA) implementation of Cisco Firepower Extensible Operating System (FXOS) and N…EPSS 4.5%7.8CVE-2020-3171Cisco ucs manager os command injection vulnerabilityA vulnerability in the local management (local-mgmt) CLI of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local at…EPSS 0.48%7.4CVE-2021-34714Cisco fxos improper input validation vulnerabilityA vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXOS Software, Cisco IOS Software, Cisco IOS XE Software, Cisco IOS XR S…EPSS 0.39%7.2CVE-2018-0300Cisco fxos path traversal vulnerabilityA vulnerability in the process of uploading new application images to Cisco FXOS on the Cisco Firepower 4100 Series Next-Generation Firewall (NGFW) a…EPSS 7.2%6.7CVE-2023-20015Cisco ucs central software os command injection vulnerabilityA vulnerability in the CLI of Cisco Firepower 4100 Series, Cisco Firepower 9300 Security Appliances, and Cisco UCS 6200, 6300, 6400, and 6500 Series …EPSS 0.22%6.7CVE-2018-0294Cisco nx-os permissions and access controls vulnerabilityA vulnerability in the write-erase feature of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to configure …EPSS 0.45%6.5CVE-2020-3120Cisco firepower extensible operating system integer overflow vulnerabilityA vulnerability in the Cisco Discovery Protocol implementation for Cisco FXOS Software, Cisco IOS XR Software, and Cisco NX-OS Software could allow a…EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2023-20016), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.