CVE-2024-20432

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Oct 2, 2024
Updated: Oct 8, 2024
CWE ID 77

Summary

CVE-2024-20432 is a newlydiscovered vulnerability in the REST API and web UI of Cisco Nexus Dashboard Fabric Controller (NDFC). This issue allows authenticated, low-privileged, remote attackers to conduct command injection attacks on affected devices. The root cause is insufficient user authorization and inadequate validation of command arguments. An attacker can exploit this vulnerability by submitting maliciously crafted commands to an API endpoint or through the web UI. Successful exploitation enables the attacker to execute arbitrary commands on the affected device's CLI with network-admin privileges. However, this vulnerability does not pose a threat to Cisco NDFC when it is configured for storage area network (SAN) controller deployment.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share