CVE-2024-20442
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2024-20442 is a vulnerability affecting the REST API endpoints of Cisco Nexus Dashboard. This issue allows authenticated, low-privileged remote attackers to execute limited Administrator functions, such as viewing web UI portions, generating backups, and deleting tech support files. The vulnerability arises due to insufficient authorization controls on certain REST API endpoints. An attacker can exploit this by sending crafted API requests to an affected endpoint. It is important to note that this vulnerability only impacts a subset of REST API endpoints and does not affect the web-based management interface.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Cisco