CVE-2024-20448

CVSS 3.1 Score 8.6 of 10 (high)

Details

Published Oct 2, 2024
Updated: Oct 8, 2024
CWE ID 312
CWE ID 313

Summary

CVE-2024-20448 is a vulnerability affecting the Cisco Nexus Dashboard Fabric Controller (NDFC) software. This issue arises from the insecure storage of sensitive information within config only and full backup files. An attacker with access to these backup files can parse their contents to obtain sensitive information, such as NDFC-connected device credentials, the NDFC site manager private key, and the scheduled backup file encryption key. This vulnerability poses a risk as it allows unauthorized access to critical information, potentially enabling further attacks on affected NDFC-connected devices.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share