PT-2024-8629 · Cisco · Cisco Nexus Dashboard Fabric Controller

Rohan Rao

·

Published

2024-10-02

·

Updated

2024-10-08

·

CVE-2024-20444

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:S/C:N/I:C/A:P
Name of the Vulnerable Software and Affected Versions Cisco Nexus Dashboard Fabric Controller (NDFC) versions not specified
Description A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, remote attacker with network-admin privileges to perform a command injection attack against an affected device. This vulnerability is due to insufficient validation of command arguments. An attacker could exploit this vulnerability by submitting crafted command arguments to a specific REST API endpoint. A successful exploit could allow the attacker to overwrite sensitive files or crash a specific container, which would restart on its own, causing a low-impact denial of service (DoS) condition.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Argument Injection

Weakness Enumeration

Related Identifiers

BDU:2024-10218
CVE-2024-20444

Affected Products

Cisco Nexus Dashboard Fabric Controller