CVE-2024-20432

CWE-77Command Injection4 documents4 sources
Severity
8.8HIGH
EPSS
2.6%
top 14.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 2

Description

A vulnerability in the REST API and web UI of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, low-privileged, remote attacker to perform a command injection attack against an affected device. This vulnerability is due to improper user authorization and insufficient validation of command arguments. An attacker could exploit this vulnerability by submitting crafted commands to an affected REST API endpoint or through the web UI. A successful exploit could allow the at

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HExploitability: 3.1 | Impact: 6.0

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-whcp-4cj3-66x2: A vulnerability in the REST API and web UI of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, low-privileged, remote atta2024-10-02
CVEList
Cisco Nexus Dashboard Fabric Controller Web UI Command Injection Vulnerability2024-10-02

📋Vendor Advisories

1
Cisco
Cisco Nexus Dashboard Fabric Controller Arbitrary Command Execution Vulnerability2024-10-02
CVE-2024-20432 (HIGH CVSS 8.8) | A vulnerability in the REST API and | cvebase.io