CVE-2023-20040 is a medium-severity denial-of-service (DoS) vulnerability affecting the NETCONF service in Cisco Network Services Orchestrator (NSO) when running as the root user. An authenticated remote attacker, belonging to the admin group, can exploit this by uploading a specially crafted package file due to improper input validation. This allows writing or deleting arbitrary files, leading to a DoS condition. Currently, there is no public exploit code, active exploitation, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.3, < 5.4.7CPE matchmatch criteria | cpe:2.3:a:cisco:network_services_orchestrator:*:*:*:*:*:*:*:* | ||
>= 5.5, < 5.5.6CPE matchmatch criteria | cpe:2.3:a:cisco:network_services_orchestrator:*:*:*:*:*:*:*:* | ||
>= 5.6, < 5.6.7CPE matchmatch criteria | cpe:2.3:a:cisco:network_services_orchestrator:*:*:*:*:*:*:*:* | ||
>= 5.7, < 5.7.4CPE matchmatch criteria | cpe:2.3:a:cisco:network_services_orchestrator:*:*:*:*:*:*:*:* | ||
5.8CPE matchmatch criteria | cpe:2.3:a:cisco:network_services_orchestrator:5.8:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.