PT-2024-8629 · Cisco · Cisco Nexus Dashboard Fabric Controller
Rohan Rao
·
Published
2024-10-02
·
Updated
2024-10-08
·
CVE-2024-20444
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:S/C:N/I:C/A:P |
Name of the Vulnerable Software and Affected Versions
Cisco Nexus Dashboard Fabric Controller (NDFC) versions not specified
Description
A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, remote attacker with network-admin privileges to perform a command injection attack against an affected device. This vulnerability is due to insufficient validation of command arguments. An attacker could exploit this vulnerability by submitting crafted command arguments to a specific REST API endpoint. A successful exploit could allow the attacker to overwrite sensitive files or crash a specific container, which would restart on its own, causing a low-impact denial of service (DoS) condition.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Nexus Dashboard Fabric Controller