Vulnslist

Cisco vulnerabilities by product, model, software, and advisory.

Cisco ACI Multi-Site CloudSec Encryption Information Disclosure Vulnerability

cisco-sa-aci-cloudsec-enc-Vs5Wn2sX · High · Published · Updated

A vulnerability in the Cisco ACI Multi-Site CloudSec encryption feature of Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an unauthenticated, remote attacker to read or modify intersite encrypted traffic. This vulnerability is due to an issue with the implementation of the ciphers that are used by the CloudSec encryption feature on affected switches. An attacker with an on-path position between the ACI sites could exploit this vulnerability by intercepting intersite encrypted traffic and using cryptanalytic techniques to break the encryption. A successful exploit could allow the attacker to read or modify the traffic that is transmitted between the sites. Cisco has deprecated and removed the ACI Multi-Site CloudSec encryption feature that is affected by this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-aci-cloudsec-enc-Vs5Wn2sX

Cisco advisory · CSAF JSON

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2023-20185
Cisco Bug IDsCSCwf02544
CVSS ScoreBase 7.4
Base 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N/E:X/RL:X/RC:X
Product Names From Source
Cisco NX-OS System Software in ACI Mode 14.0(1h), Cisco NX-OS System Software in ACI Mode 14.0(2c), Cisco NX-OS System Software in ACI Mode 14.0(3d), Cisco NX-OS System Software in ACI Mode 14.0(3c), Cisco NX-OS System Software in ACI Mode 14.1(1i), Cisco NX-OS System Software in ACI Mode 14.1(1j), Cisco NX-OS System Software in ACI Mode 14.1(1k), Cisco NX-OS System Software in ACI Mode 14.1(1l), Cisco NX-OS System Software in ACI Mode 14.1(2g), Cisco NX-OS System Software in ACI Mode 14.1(2m), Cisco NX-OS System Software in ACI Mode 14.1(2o), Cisco NX-OS System Software in ACI Mode 14.1(2s), Cisco NX-OS System Software in ACI Mode 14.1(2u), Cisco NX-OS System Software in ACI Mode 14.1(2w), Cisco NX-OS System Software in ACI Mode 14.1(2x), Cisco NX-OS System Software in ACI Mode 14.2(1i), Cisco NX-OS System Software in ACI Mode 14.2(1j), Cisco NX-OS System Software in ACI Mode 14.2(1l), Cisco NX-OS System Software in ACI Mode 14.2(2e), Cisco NX-OS System Software in ACI Mode 14.2(2f), Cisco NX-OS System Software in ACI Mode 14.2(2g), Cisco NX-OS System Software in ACI Mode 14.2(3j), Cisco NX-OS System Software in ACI Mode 14.2(3l), Cisco NX-OS System Software in ACI Mode 14.2(3n), Cisco NX-OS System Software in ACI Mode 14.2(3q), Cisco NX-OS System Software in ACI Mode 14.2(4i), Cisco NX-OS System Software in ACI Mode 14.2(4k), Cisco NX-OS System Software in ACI Mode 14.2(4o), Cisco NX-OS System Software in ACI Mode 14.2(4p), Cisco NX-OS System Software in ACI Mode 14.2(5k), Cisco NX-OS System Software in ACI Mode 14.2(5l), Cisco NX-OS System Software in ACI Mode 14.2(5n), Cisco NX-OS System Software in ACI Mode 14.2(6d), Cisco NX-OS System Software in ACI Mode 14.2(6g), Cisco NX-OS System Software in ACI Mode 14.2(6h), Cisco NX-OS System Software in ACI Mode 14.2(6l), Cisco NX-OS System Software in ACI Mode 14.2(7f), Cisco NX-OS System Software in ACI Mode 14.2(7l), Cisco NX-OS System Software in ACI Mode 14.2(6o), Cisco NX-OS System Software in ACI Mode 14.2(7q), Cisco NX-OS System Software in ACI Mode 14.2(7r), Cisco NX-OS System Software in ACI Mode 14.2(7s), Cisco NX-OS System Software in ACI Mode 14.2(7t), Cisco NX-OS System Software in ACI Mode 14.2(7u), Cisco NX-OS System Software in ACI Mode 14.2(7v), Cisco NX-OS System Software in ACI Mode 14.2(7w), Cisco NX-OS System Software in ACI Mode 15.0(1k), Cisco NX-OS System Software in ACI Mode 15.0(1l), Cisco NX-OS System Software in ACI Mode 15.0(2e), Cisco NX-OS System Software in ACI Mode 15.0(2h), Cisco NX-OS System Software in ACI Mode 15.1(2e), Cisco NX-OS System Software in ACI Mode 15.1(3e), Cisco NX-OS System Software in ACI Mode 15.1(4c), Cisco NX-OS System Software in ACI Mode 15.2(1g), Cisco NX-OS System Software in ACI Mode 15.2(2e), Cisco NX-OS System Software in ACI Mode 15.2(2f), Cisco NX-OS System Software in ACI Mode 15.2(2g), Cisco NX-OS System Software in ACI Mode 15.2(2h), Cisco NX-OS System Software in ACI Mode 15.2(3e), Cisco NX-OS System Software in ACI Mode 15.2(3f), Cisco NX-OS System Software in ACI Mode 15.2(3g), Cisco NX-OS System Software in ACI Mode 15.2(4d), Cisco NX-OS System Software in ACI Mode 15.2(4e), Cisco NX-OS System Software in ACI Mode 15.2(5c), Cisco NX-OS System Software in ACI Mode 15.2(5d), Cisco NX-OS System Software in ACI Mode 15.2(5e), Cisco NX-OS System Software in ACI Mode 15.2(4f), Cisco NX-OS System Software in ACI Mode 15.2(6e), Cisco NX-OS System Software in ACI Mode 15.2(6g), Cisco NX-OS System Software in ACI Mode 15.2(7f), Cisco NX-OS System Software in ACI Mode 15.2(7g), Cisco NX-OS System Software in ACI Mode 15.2(6h), Cisco NX-OS System Software in ACI Mode 15.2(8d), Cisco NX-OS System Software in ACI Mode 15.2(8e), Cisco NX-OS System Software in ACI Mode 15.2(8f), Cisco NX-OS System Software in ACI Mode 15.2(8g), Cisco NX-OS System Software in ACI Mode 15.2(8h), Cisco NX-OS System Software in ACI Mode 15.2(8i), Cisco NX-OS System Software in ACI Mode 16.0(1g), Cisco NX-OS System Software in ACI Mode 16.0(1j), Cisco NX-OS System Software in ACI Mode 16.0(2h), Cisco NX-OS System Software in ACI Mode 16.0(2j), Cisco NX-OS System Software in ACI Mode 16.0(3d), Cisco NX-OS System Software in ACI Mode 16.0(3e), Cisco NX-OS System Software in ACI Mode 16.0(4c), Cisco NX-OS System Software in ACI Mode 16.0(5h), Cisco NX-OS System Software in ACI Mode 16.0(3g), Cisco NX-OS System Software in ACI Mode 16.0(5j), Cisco NX-OS System Software in ACI Mode 16.0(6c), Cisco NX-OS System Software in ACI Mode 16.0(7e), Cisco NX-OS System Software in ACI Mode 16.0(8e), Cisco NX-OS System Software in ACI Mode 16.0(8f), Cisco NX-OS System Software in ACI Mode 16.0(9c), Cisco NX-OS System Software in ACI Mode 16.0(9d), Cisco NX-OS System Software in ACI Mode 16.0(6h), Cisco NX-OS System Software in ACI Mode 16.0(8h), Cisco NX-OS System Software in ACI Mode 16.0(9e), Cisco NX-OS System Software in ACI Mode 16.0(9f), Cisco NX-OS System Software in ACI Mode 15.3(1d), Cisco NX-OS System Software in ACI Mode 15.3(2a), Cisco NX-OS System Software in ACI Mode 15.3(2b), Cisco NX-OS System Software in ACI Mode 15.3(2c), Cisco NX-OS System Software in ACI Mode 15.3(2d), Cisco NX-OS System Software in ACI Mode 15.3(2e), Cisco NX-OS System Software in ACI Mode 15.3(2f), Cisco NX-OS System Software in ACI Mode 16.1(1f), Cisco NX-OS System Software in ACI Mode 16.1(2f), Cisco NX-OS System Software in ACI Mode 16.1(2g), Cisco NX-OS System Software in ACI Mode 16.1(3f), Cisco NX-OS System Software in ACI Mode 16.1(3g), Cisco NX-OS System Software in ACI Mode 16.1(4h), Cisco NX-OS System Software in ACI Mode 16.1(5e), Cisco NX-OS System Software in ACI Mode 16.2(1g), Cisco NX-OS System Software in ACI Mode

Related Products

Product CVE Evidence
Cisco Nexus 9000 Series Switches CVE-2023-20185 Cisco OpenVuln
Cisco NX-OS System Software in ACI Mode CVE-2023-20185 Cisco OpenVuln