CVE-2024-20385

CVSS 3.1 Score 5.9 of 10 (medium)

Details

Published Oct 2, 2024
Updated: Oct 8, 2024
CWE ID 295

Summary

CVE-2024-20385 is a vulnerability affecting the SSL/TLS implementation in Cisco Nexus Dashboard Orchestrator (NDO). This issue allows unauthenticated, remote attackers to intercept sensitive information by impersonating affected devices during communications with Cisco NDO. The vulnerability arises due to the Cisco NDO Validate Peer Certificate site management feature only validating certificates when a new site is added or an existing one is reregistered. Attackers can exploit this by using machine-in-the-middle techniques to intercept traffic and present a crafted certificate, potentially gaining unauthorized access to sensitive information.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share