PT-2024-8626 · Cisco · Cisco Nexus Dashboard

Published

2024-10-02

·

Updated

2024-10-07

·

CVE-2024-20442

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Cisco Nexus Dashboard (affected versions not specified)
Description A vulnerability in the REST API endpoints of Cisco Nexus Dashboard could allow an authenticated, low-privileged, remote attacker to perform limited Administrator actions on an affected device. This issue is due to insufficient authorization controls on some REST API endpoints. An attacker could exploit this vulnerability by sending crafted API requests to an affected endpoint, potentially allowing them to perform limited Administrator functions such as viewing portions of the web UI, generating config only or full backup files, and deleting tech support files.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2024-10214
CVE-2024-20442

Affected Products

Cisco Nexus Dashboard