Rewterz penetration testing services help organizations determine if a cyber attacker can gain access to their critical assets while giving them detailed insights of the overall business impact of a cyber attack.
Before Rewterz got its start, the market was in dire need of a specialized and dedicated information security company. It was nearly impossible for businesses to find a trustworthy provider that could truly cover all of their bases. We wanted to meet this need, giving companies across the globe a chance to get ahead while knowing that their data is in good hands.
Rewterz penetration testing services help organizations determine if a cyber attacker can gain access to their critical assets while giving them detailed insights of the overall business impact of a cyber attack.
Before Rewterz got its start, the market was in dire need of a specialized and dedicated information security company. It was nearly impossible for businesses to find a trustworthy provider that could truly cover all of their bases. We wanted to meet this need, giving companies across the globe a chance to get ahead while knowing that their data is in good hands.
Medium
CVE-2023-20168 CVSS:7.1
Cisco NX-OS Software is vulnerable to a denial of service, caused by improper input validation when processing an authentication attempt when the directed request option is enabled for TACACS+ or RADIUS. By sending a specially crafted request, a remote attacker could exploit this vulnerability to cause the device to reload unexpectedly, and results in a denial of service condition.
CVE-2023-20169 CVSS:7.4
Cisco Nexus 3000 and 9000 Series Switches are vulnerable to a denial of service, caused by improper input validation when parsing an ingress IS-IS packet. By sending a specially crafted IS-IS packet, a remote attacker could exploit this vulnerability to cause the IS-IS process to restart unexpectedly, and results in a denial of service condition.
CVE-2023-20200 CVSS:7.7
Cisco Firepower 4100 Series, Firepower 9300 Security Appliances, and UCS 6300 Series Fabric Interconnects are vulnerable to a denial of service, caused by improper handling of specific SNMP requests. By sending a specially crafted SNMP request, a remote authenticated attacker could exploit this vulnerability to cause the device to reload, and results in a denial of service condition.
CVE-2023-20115 CVSS:5.4
Cisco Nexus 3000 and 9000 Series Switches could allow a remote authenticated attacker to bypass security restrictions, caused by a logic error when verifying the user role when an SFTP connection is opened. By sending a specially crafted request, an attacker could exploit this vulnerability to read or overwrite files from the underlying operating system with the privileges of the authenticated user.
CVE-2023-20234 CVSS:4.4
Cisco FXOS Software could allow a local authenticated attacker to bypass security restrictions, caused by improper validating parameters when a specific CLI command is used. By sending a specially crafted CLI command, an attacker could exploit this vulnerability to overwrite arbitrary files on the disk.
CVE-2023-20230 CVSS:5.4
Cisco Application Policy Infrastructure Controller (APIC) could allow a remote authenticated attacker to bypass security restrictions, caused by improper access control when restricted security domains are used. By sending a specially crafted request, an attacker could exploit this vulnerability to read, modify, or delete policies created by users associated with a different security domain.
Cisco
Refer to Cisco Security Advisory for patch, upgrade or suggested workaround information.