Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Whitej6

#44878of 53,630
5.7Total CVSS
Vulnerabilities · 1
PT-2023-30909
5.7
2023-11-21
Nautobot · Nautobot Device Onboarding Plugin · CVE-2023-48700
**Name of the Vulnerable Software and Affected Versions** Nautobot Device Onboarding plugin versions 2.0.0 through 2.0.2 Nautobot Device Onboarding plugin versions 2.0.0 through 2.0.x **Description** The Nautobot Device Onboarding plugin uses the netmiko and NAPALM libraries to simplify the onboarding process of a new device into Nautobot. Credentials provided to onboarding tasks are visible via Job Results from an execution of an Onboarding Task. This issue is fixed in version 3.0.0. **Recommendations** For versions 2.0.0 through 2.0.2, delete all Job Results for any onboarding task to remove clear text credentials from database entries. For versions 2.0.0 through 2.0.x, upgrade to version 3.0.0. Rotate any exposed credentials.