Cisco Nexus 9000 Information Disclosure (CVE-2023-20185)

high Tenable OT Security Plugin ID 501947

Synopsis

The remote OT asset is affected by a vulnerability.

Description

A vulnerability in the Cisco ACI Multi-Site CloudSec encryption feature of Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an unauthenticated, remote attacker to read or modify intersite encrypted traffic. This vulnerability is due to an issue with the implementation of the ciphers that are used by the CloudSec encryption feature on affected switches. An attacker with an on-path position between the ACI sites could exploit this vulnerability by intercepting intersite encrypted traffic and using cryptanalytic techniques to break the encryption. A successful exploit could allow the attacker to read or modify the traffic that is transmitted between the sites.
Cisco has not released and will not release software updates that address this vulnerability.

This plugin only works with Tenable.ot.
Please visit https://www.tenable.com/products/tenable-ot for more information.

Solution

Cisco has not released and will not release software updates to address the vulnerability that is described in this advisory. Customers who are using the Cisco ACI Multi-Site CloudSec encryption feature for the Cisco Nexus 9332C and Nexus 9364C Switches and the Cisco Nexus N9K-X9736C-FX Line Card are advised to disable this feature and to contact their support organization to evaluate alternative options, such as performing encryption on the underlying site-to-site connections. There are no alternatives that provide full encryption for data in transit between sites on current ACI Spine Switches hardware.

When considering software upgrades, customers are advised to regularly consult the advisories for Cisco products, which are available from the Cisco Security Advisories page, to determine exposure and a complete upgrade solution. In all cases, customers should ensure that the devices to be upgraded contain sufficient memory and confirm that current hardware and software configurations will continue to be supported properly by the new release. If the information is not clear, customers are advised to contact the Cisco Technical Assistance Center (TAC) or their contracted maintenance providers.

Please refer to the vendor advisory for more information.

See Also

http://www.nessus.org/u?54db6797

Plugin Details

Severity: High

ID: 501947

Version: 1.1

Type: remote

Family: Tenable.ot

Published: 1/31/2024

Updated: 2/1/2024

Supported Sensors: Tenable OT Security

Risk Information

VPR

Risk Factor: Medium

Score: 5.2

CVSS v2

Risk Factor: High

Base Score: 7.1

Temporal Score: 5.3

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:N

CVSS Score Source: CVE-2023-20185

CVSS v3

Risk Factor: High

Base Score: 7.4

Temporal Score: 6.4

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:cisco:nx-os:14.0%283d%29, cpe:/o:cisco:nx-os:14.1%281i%29, cpe:/o:cisco:nx-os:14.1%281j%29, cpe:/o:cisco:nx-os:14.1%281k%29, cpe:/o:cisco:nx-os:14.1%281l%29, cpe:/o:cisco:nx-os:14.1%282g%29, cpe:/o:cisco:nx-os:14.1%282m%29, cpe:/o:cisco:nx-os:14.1%282o%29, cpe:/o:cisco:nx-os:14.0%281h%29, cpe:/o:cisco:nx-os:14.0%282c%29, cpe:/o:cisco:nx-os:14.0%283c%29, cpe:/o:cisco:nx-os:14.1%282s%29, cpe:/o:cisco:nx-os:14.1%282u%29, cpe:/o:cisco:nx-os:14.1%282w%29, cpe:/o:cisco:nx-os:14.1%282x%29, cpe:/o:cisco:nx-os:14.2%281i%29, cpe:/o:cisco:nx-os:14.2%281j%29, cpe:/o:cisco:nx-os:15.2%282e%29, cpe:/o:cisco:nx-os:14.2%281l%29, cpe:/o:cisco:nx-os:14.2%282e%29, cpe:/o:cisco:nx-os:14.2%282f%29, cpe:/o:cisco:nx-os:14.2%282g%29, cpe:/o:cisco:nx-os:14.2%283j%29, cpe:/o:cisco:nx-os:14.2%283l%29, cpe:/o:cisco:nx-os:14.2%283n%29, cpe:/o:cisco:nx-os:14.2%283q%29, cpe:/o:cisco:nx-os:14.2%284i%29, cpe:/o:cisco:nx-os:14.2%284k%29, cpe:/o:cisco:nx-os:14.2%284o%29, cpe:/o:cisco:nx-os:14.2%284p%29, cpe:/o:cisco:nx-os:14.2%285k%29, cpe:/o:cisco:nx-os:14.2%285l%29, cpe:/o:cisco:nx-os:14.2%285n%29, cpe:/o:cisco:nx-os:14.2%286d%29, cpe:/o:cisco:nx-os:15.2%282f%29, cpe:/o:cisco:nx-os:15.2%282g%29, cpe:/o:cisco:nx-os:15.2%282h%29, cpe:/o:cisco:nx-os:15.2%283e%29, cpe:/o:cisco:nx-os:15.2%283f%29, cpe:/o:cisco:nx-os:15.2%283g%29, cpe:/o:cisco:nx-os:15.2%284d%29, cpe:/o:cisco:nx-os:15.2%284e%29, cpe:/o:cisco:nx-os:15.2%284f%29, cpe:/o:cisco:nx-os:15.2%285c%29, cpe:/o:cisco:nx-os:15.2%285d%29, cpe:/o:cisco:nx-os:15.2%285e%29, cpe:/o:cisco:nx-os:15.2%286e%29, cpe:/o:cisco:nx-os:15.2%286g%29, cpe:/o:cisco:nx-os:15.2%287f%29, cpe:/o:cisco:nx-os:15.2%287g%29, cpe:/o:cisco:nx-os:15.2%288d%29, cpe:/o:cisco:nx-os:16.0%281g%29, cpe:/o:cisco:nx-os:16.0%281j%29, cpe:/o:cisco:nx-os:16.0%282h%29, cpe:/o:cisco:nx-os:14.2%286g%29, cpe:/o:cisco:nx-os:14.2%286h%29, cpe:/o:cisco:nx-os:14.2%286l%29, cpe:/o:cisco:nx-os:14.2%286o%29, cpe:/o:cisco:nx-os:14.2%287f%29, cpe:/o:cisco:nx-os:14.2%287l%29, cpe:/o:cisco:nx-os:14.2%287q%29, cpe:/o:cisco:nx-os:14.2%287r%29, cpe:/o:cisco:nx-os:14.2%287s%29, cpe:/o:cisco:nx-os:14.2%287t%29, cpe:/o:cisco:nx-os:14.2%287u%29, cpe:/o:cisco:nx-os:14.2%287v%29, cpe:/o:cisco:nx-os:14.2%287w%29, cpe:/o:cisco:nx-os:15.0%281k%29, cpe:/o:cisco:nx-os:15.0%281l%29, cpe:/o:cisco:nx-os:15.0%282e%29, cpe:/o:cisco:nx-os:15.0%282h%29, cpe:/o:cisco:nx-os:15.1%281h%29, cpe:/o:cisco:nx-os:15.1%282e%29, cpe:/o:cisco:nx-os:15.1%283e%29, cpe:/o:cisco:nx-os:15.1%284c%29, cpe:/o:cisco:nx-os:15.2%281g%29

Required KB Items: Tenable.ot/Cisco

Exploit Ease: No known exploits are available

Patch Publication Date: 7/12/2023

Vulnerability Publication Date: 7/12/2023

Reference Information

CVE: CVE-2023-20185

CWE: 326, 330