CVE-2024-20385
CVSS 3.1 Score 5.9 of 10 (medium)
Details
Summary
CVE-2024-20385 is a vulnerability affecting the SSL/TLS implementation in Cisco Nexus Dashboard Orchestrator (NDO). This issue allows unauthenticated, remote attackers to intercept sensitive information by impersonating affected devices during communications with Cisco NDO. The vulnerability arises due to the Cisco NDO Validate Peer Certificate site management feature only validating certificates when a new site is added or an existing one is reregistered. Attackers can exploit this by using machine-in-the-middle techniques to intercept traffic and present a crafted certificate, potentially gaining unauthorized access to sensitive information.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Cisco