CVE-2023-20014 is a denial-of-service vulnerability in the DNS functionality of Cisco Nexus Dashboard Software. An unauthenticated, remote attacker can exploit this by sending a continuous stream of DNS requests, causing the coredns service to stop or the device to reload. Rated 7.5 HIGH on CVSS, it has a low attack complexity and high impact on availability, with no confidentiality or integrity impact. Currently, there is no evidence of active exploitation, public exploit code, or inclusion in CISA's KEV catalog, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.3\(1c\)CPE matchmatch criteria | cpe:2.3:a:cisco:nexus_dashboard:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.