PT-2024-2563 · Cisco · Cisco Nexus Dashboard Fabric Controller

Published

2024-04-03

·

Updated

2024-04-03

·

CVE-2024-20348

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco Nexus Dashboard Fabric Controller (NDFC) (affected versions not specified)
Description A vulnerability in the Out-of-Band (OOB) Plug and Play (PnP) feature of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauthenticated, remote attacker to read arbitrary files. This issue is due to an unauthenticated provisioning web server and incorrect restriction of the directory path name, allowing an attacker to exploit the vulnerability through direct web requests to the provisioning server. A successful exploit could allow the attacker to read sensitive files in the PnP container, potentially facilitating further attacks on the PnP infrastructure.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2024-02601
CVE-2024-20348

Affected Products

Cisco Nexus Dashboard Fabric Controller