CVE-2023-20161 is a critical vulnerability affecting the web-based user interface of certain Cisco Small Business Series Switches. It stems from improper validation of web requests, allowing an unauthenticated, remote attacker to achieve a denial of service or execute arbitrary code with root privileges. With a CVSS score of 9.8 (Critical), this vulnerability has a low attack complexity and severe impacts on confidentiality, integrity, and availability. Although not listed in CISA's KEV catalog, public exploit code is available, and it has garnered significant community discussion and media coverage, including reports of proof-of-concept exploits.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:cisco:business_250-16p-2g_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:cisco:business_250-16t-2g_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:cisco:business_250-24fp-4g_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:cisco:business_250-24fp-4x_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:cisco:business_250-24p-4g_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.