CVE-2023-20185 is a critical vulnerability in the Cisco ACI Multi-Site CloudSec encryption feature of Cisco Nexus 9000 Series Fabric Switches in ACI mode. This flaw, stemming from an issue with the ciphers used, allows an unauthenticated, remote attacker with an on-path position to read or modify intersite encrypted traffic. The vulnerability carries a high CVSS score of 7.4 due to its network attack vector, high impact on confidentiality and integrity, and no user interaction required. While Cisco has not released a patch, there is no evidence of active exploitation, nor is public exploit code available; however, it has garnered significant community discussion and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
14.0\(1h\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:14.0\(1h\):*:*:*:*:*:*:* | ||
14.0\(2c\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:14.0\(2c\):*:*:*:*:*:*:* | ||
14.0\(3c\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:14.0\(3c\):*:*:*:*:*:*:* | ||
14.0\(3d\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:14.0\(3d\):*:*:*:*:*:*:* | ||
14.1\(1i\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:14.1\(1i\):*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.