Rewterz penetration testing services help organizations determine if a cyber attacker can gain access to their critical assets while giving them detailed insights of the overall business impact of a cyber attack.
Before Rewterz got its start, the market was in dire need of a specialized and dedicated information security company. It was nearly impossible for businesses to find a trustworthy provider that could truly cover all of their bases. We wanted to meet this need, giving companies across the globe a chance to get ahead while knowing that their data is in good hands.
Rewterz penetration testing services help organizations determine if a cyber attacker can gain access to their critical assets while giving them detailed insights of the overall business impact of a cyber attack.
Before Rewterz got its start, the market was in dire need of a specialized and dedicated information security company. It was nearly impossible for businesses to find a trustworthy provider that could truly cover all of their bases. We wanted to meet this need, giving companies across the globe a chance to get ahead while knowing that their data is in good hands.
Medium
CVE-2023-20016 CVSS:6.3
Cisco FXOS Software and UCS Manager Software could allow a local attacker to obtain sensitive information, caused by a flaw in the encryption method used for the backup function. By sending a specially-crafted HTTP request, an attacker could exploit this vulnerability to obtain sensitive information stored in full state and configuration backup files, and use this information to launch further attacks against the affected system.
CVE-2023-20050 CVSS:4.4
Cisco NX-OS Software could allow a local authenticated attacker to execute arbitrary commands on the system, caused by improper validation of arguments that are passed to specific CLI commands. By sending a specially-crafted input as the argument, an attacker could exploit this vulnerability to execute arbitrary commands on the underlying operating system with the privileges of the currently logged-in user.
CVE-2023-20015 CVSS:6
Cisco Firepower 4100, 9300 Security Appliances, and UCS Fabric Interconnects could allow a local authenticated attacker to execute arbitrary commands on the system, caused by improper input validation of commands supplied by the user. By sending a specially-crafted input, an attacker could exploit this vulnerability to execute arbitrary commands on the underlying operating system with root-level privileges.
Cisco
Cisco Firepower 9300 Security Appliances
Cisco UCS 6200 Series Fabric Interconnects
Cisco UCS 6300 Series Fabric Interconnects
Cisco FXOS Software
Cisco UCS 6400 Series Fabric Interconnects
Cisco Firepower 4100 Series
Cisco UCS Manager software
Cisco UCS 6500 Series Fabric Interconnects
Cisco Nexus 3000 Series Switches
Cisco MDS 9000 Series Multilayer Switches
Cisco Nexus 6000 Series Switches
Cisco Nexus 7000 Series Switches
Cisco Nexus 5500 Platform Switches
Cisco Nexus 5600 Platform Switches
Cisco NX-OS Software
Cisco Nexus 9000 Series Switches in standalone NX-OS mode
Cisco Nexus 1000V Switch for Microsoft Hyper-V
Cisco Nexus 1000V Switch for VMware vSphere
Cisco Nexus 1000 Virtual Edge for VMware vSphere
Refer to Cisco Security Advisory for patch, upgrade or suggested workaround information.