PT-2024-3821 · Cisco · Cisco Nexus Dashboard
Cooper Timewell
·
Published
2024-04-03
·
Updated
2025-05-07
·
CVE-2024-20282
CVSS v2.0
6.2
Medium
| Vector | AV:L/AC:L/Au:S/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Nexus Dashboard (affected versions not specified)
Description
The issue is related to insufficient access control protections, which could allow an authenticated, local attacker with valid credentials to elevate privileges to root on an affected device. This is due to inadequate protections for a sensitive access token, which an attacker could exploit to access resources within the device infrastructure, potentially gaining root access to the filesystem or hosted containers.
Recommendations
For all affected versions, consider restricting access to sensitive resources and tokens until a patch is available.
As a temporary workaround, limit the use of rescue-user credentials to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Privilege Management
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Nexus Dashboard