cbcvebase.
CVE-2024-20449
published 2024-10-02

CVE-2024-20449: A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, remote attacker with low privileges to execute arbitrary code…

PriorityP263high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.94%
56.9th percentile
A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, remote attacker with low privileges to execute arbitrary code on an affected device. This vulnerability is due to improper path validation. An attacker could exploit this vulnerability by using the Secure Copy Protocol (SCP) to upload malicious code to an affected device using path traversal techniques. A successful exploit could allow the attacker to execute arbitrary code in a specific container with the privileges of root.

Affected

13 ranges
VendorProductVersion rangeFixed in
ciscocisco_data_center_network_manager
ciscocisco_data_center_network_manager
ciscocisco_data_center_network_manager
ciscocisco_data_center_network_manager
ciscocisco_data_center_network_manager
ciscocisco_data_center_network_manager
ciscocisco_data_center_network_manager
ciscocisco_data_center_network_manager
ciscocisco_data_center_network_manager
ciscocisco_data_center_network_manager
ciscocisco_data_center_network_manager
cisconexus_dashboard_fabric_controller
cisconexus_dashboard_fabric_controller12.0.0 – 12.2.2

Detection & IOCsextracted from sources · hover to see the quote

  • Detect exploitation attempts via SCP-based path traversal uploads to Cisco NDFC — monitor for SCP sessions from low-privileged authenticated users that include path traversal sequences (e.g., '../') in the destination path
  • Alert on unexpected file writes or process execution originating from the NDFC container context running as root, which may indicate successful exploitation of this path traversal RCE
  • Track Cisco internal bug ID CSCwk04223 for vendor patch and detection content updates related to this vulnerability
  • ·No workarounds are available for this vulnerability; the only remediation is applying Cisco's software updates
  • ·Exploitation requires an authenticated attacker with low privileges, meaning unauthenticated access alone is insufficient — focus detection on authenticated SCP activity from low-privilege accounts
  • ·The root-level code execution is scoped to a specific container, not the full host OS — forensic investigation should focus on container-level artifacts

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_cisco8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.