CVE-2024-20432
published 2024-10-02CVE-2024-20432: A vulnerability in the REST API and web UI of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, low-privileged, remote attacker to…
PriorityP265high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.14%
62.9th percentile
A vulnerability in the REST API and web UI of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, low-privileged, remote attacker to perform a command injection attack against an affected device.
This vulnerability is due to improper user authorization and insufficient validation of command arguments. An attacker could exploit this vulnerability by submitting crafted commands to an affected REST API endpoint or through the web UI. A successful exploit could allow the attacker to execute arbitrary commands on the CLI of a Cisco NDFC-managed device with network-admin privileges.
Note: This vulnerability does not affect Cisco NDFC when it is configured for storage area network (SAN) controller deployment.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_data_center_network_manager | — | — |
| cisco | cisco_data_center_network_manager | — | — |
| cisco | cisco_data_center_network_manager | — | — |
| cisco | cisco_data_center_network_manager | — | — |
| cisco | cisco_data_center_network_manager | — | — |
| cisco | cisco_data_center_network_manager | — | — |
| cisco | cisco_data_center_network_manager | — | — |
| cisco | cisco_data_center_network_manager | — | — |
| cisco | cisco_data_center_network_manager | — | — |
| cisco | cisco_data_center_network_manager | — | — |
| cisco | cisco_data_center_network_manager | — | — |
| cisco | nexus_dashboard_fabric_controller | — | — |
| cisco | nexus_dashboard_fabric_controller | >= 12.0.0 < 12.2.2 | 12.2.2 |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for crafted command submissions to the Cisco NDFC REST API endpoints by authenticated low-privileged users, which may indicate command injection attempts. ↗
- →Alert on low-privileged NDFC users executing CLI commands with network-admin privileges on managed devices, as this is the expected outcome of a successful exploit. ↗
- →Scope detection to LAN fabric controller deployments only; SAN controller deployments are not affected and should be excluded from alerting logic. ↗
- →Track Cisco internal bug ID CSCwj10299 for vendor patch and indicator updates related to this vulnerability. ↗
- ·Vulnerability is only exploitable by authenticated users; unauthenticated access does not trigger this attack path. Ensure authentication logging is enabled on NDFC to support forensic investigation. ↗
- ·No workarounds exist; the only remediation is applying Cisco's released software updates. Detection controls are compensating only until patching is complete. ↗
- ·Root cause is dual: improper user authorization AND insufficient validation of command arguments (CWE-77). Detection rules should cover both the REST API and web UI attack surfaces. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_cisco9.9CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-whcp-4cj3-66x2: A vulnerability in the REST API and web UI of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, low-privileged, remote atta
ghsa_unreviewed·2024-10-02
CVE-2024-20432 [CRITICAL] CWE-77 GHSA-whcp-4cj3-66x2: A vulnerability in the REST API and web UI of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, low-privileged, remote atta
A vulnerability in the REST API and web UI of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, low-privileged, remote attacker to perform a command injection attack against an affected device.
This vulnerability is due to improper user authorization and insufficient validation of command arguments. An attacker could exploit this vulnerability by submitting crafted commands to an affected REST API endpoint or through the web UI. A successful exploit could allow the attacker to execute arbitrary commands on the CLI of a Cisco NDFC-managed device with network-admin privileges.
Note: This vulnerability does not affect Cisco NDFC when it is configured for storage area network (SAN) controller deployment.
Cisco
Cisco Nexus Dashboard Fabric Controller Arbitrary Command Execution Vulnerability
vendor_cisco·2024-10-02·CVSS 9.9
CVE-2024-20432 [CRITICAL] CWE-77 Cisco Nexus Dashboard Fabric Controller Arbitrary Command Execution Vulnerability
Cisco Nexus Dashboard Fabric Controller Arbitrary Command Execution Vulnerability
A vulnerability in the REST API and web UI of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, low-privileged, remote attacker to perform a command injection attack against an affected device.
This vulnerability is due to improper user authorization and insufficient validation of command arguments. An attacker could exploit this vulnerability by submitting crafted commands to an affected REST API endpoint or through the web UI. A successful exploit could allow the attacker to execute arbitrary commands on the CLI of a Cisco NDFC-managed device with network-admin privileges.
Note: This vulnerability does not affect Cisco NDFC when it is configured for storage area network (SAN)
Cisco
Cisco Nexus Dashboard Fabric Controller Arbitrary Command Execution Vulnerability
vendor_cisco·CVSS 3.1
CVE-2024-20432 Cisco Nexus Dashboard Fabric Controller Arbitrary Command Execution Vulnerability
CVE-2024-20432: Cisco Nexus Dashboard Fabric Controller Arbitrary Command Execution Vulnerability
A vulnerability in the REST API and web UI of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, low-privileged, remote attacker to perform a command injection attack against an affected device. This vulnerability is due to improper user authorization and insufficient validation of command arguments. An attacker could exploit this vulnerability by submitting crafted commands to an affected REST API endpoint or through the web UI. A successful exploit could allow the attacker to execute arbitrary commands on the CLI of a Cisco NDFC-managed device with network-admin privileges. Note: This vulnerability does not affect Cisco NDFC when it is configured for storage area ne
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-10-02
Published