Vulnerability Intelligence Report
CVE-2023-20263
A vulnerability in the web-based management interface of Cisco HyperFlex HX Data Platform could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of the parameters in an HTTP request. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to redirect a user to a malicious website.
No Active Exploit Signals
CVSS Base Score
4.7
MEDIUM
Exploitability:2.9
Impact Score:1.5
EPSS Probability:0.48%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-601 ↗URL Redirection to Untrusted Site ('Open Redirect')
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Cisco | Cisco HyperFlex HX Data Platform | 4.0(1a) (affected), 4.0(1b) (affected), 4.0(2a) (affected), 4.0(2b) (affected), 4.0(2c) (affected), 4.0(2d) (affected), 4.0(2e) (affected), 4.0(2f) (affected), 4.5(1a) (affected), 4.5(2a) (affected), 4.5(2b) (affected), 4.5(2c) (affected), 4.5(2d) (affected), 4.5(2e) (affected), 5.0(1a) (affected), 5.0(1b) (affected), 5.0(1c) (affected), 5.0(2a) (affected), 5.0(2b) (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.480%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Cisco Systems, Inc. · Hosted Service · USA |
| Reserved | 2022-10-27T18:47:50 |
| Published | 2023-09-06T17:10:31 |
| Last Updated | 2024-11-21T21:42:51 |
Community Chatter & Buzz