PT-2024-2563 · Cisco · Cisco Nexus Dashboard Fabric Controller
Published
2024-04-03
·
Updated
2024-04-03
·
CVE-2024-20348
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Nexus Dashboard Fabric Controller (NDFC) (affected versions not specified)
Description
A vulnerability in the Out-of-Band (OOB) Plug and Play (PnP) feature of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauthenticated, remote attacker to read arbitrary files. This issue is due to an unauthenticated provisioning web server and incorrect restriction of the directory path name, allowing an attacker to exploit the vulnerability through direct web requests to the provisioning server. A successful exploit could allow the attacker to read sensitive files in the PnP container, potentially facilitating further attacks on the PnP infrastructure.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Nexus Dashboard Fabric Controller