Encryption Vulnerability in Cisco Nexus 9000 Series Switches
CVE-2023-20185
Key Information:
- Vendor
Cisco
- Vendor
- CVE Published:
- 12 July 2023
What is CVE-2023-20185?
A vulnerability exists within the CloudSec encryption feature of Cisco Nexus 9000 Series Fabric Switches in ACI mode, allowing an unauthenticated remote attacker to potentially read or modify encrypted intersite traffic. This issue stems from a weakness in the implementation of ciphers utilized for encryption. An attacker positioned on the path between ACI sites can exploit this vulnerability, employing cryptanalytic techniques to compromise the encryption. As a result, affected traffic may be intercepted and altered. Notably, Cisco has indicated that they will not release any software updates to remedy this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cisco NX-OS System Software in ACI Mode 14.0(1h)
Cisco NX-OS System Software in ACI Mode 14.0(2c)
Cisco NX-OS System Software in ACI Mode 14.0(3d)
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved