PT-2024-3821 · Cisco · Cisco Nexus Dashboard

Cooper Timewell

·

Published

2024-04-03

·

Updated

2025-05-07

·

CVE-2024-20282

CVSS v2.0

6.2

Medium

VectorAV:L/AC:L/Au:S/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Cisco Nexus Dashboard (affected versions not specified)
Description The issue is related to insufficient access control protections, which could allow an authenticated, local attacker with valid credentials to elevate privileges to root on an affected device. This is due to inadequate protections for a sensitive access token, which an attacker could exploit to access resources within the device infrastructure, potentially gaining root access to the filesystem or hosted containers.
Recommendations For all affected versions, consider restricting access to sensitive resources and tokens until a patch is available. As a temporary workaround, limit the use of rescue-user credentials to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Privilege Management

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

BDU:2024-04197
CVE-2024-20282

Affected Products

Cisco Nexus Dashboard