CVE-2024-20536
published 2024-11-06CVE-2024-20536: A vulnerability in a REST API endpoint and web-based management interface of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated…
PriorityP263high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.77%
51.4th percentile
A vulnerability in a REST API endpoint and web-based management interface of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, remote attacker with read-only privileges to execute arbitrary SQL commands on an affected device.
This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to a specific REST API endpoint or web-based management interface. A successful exploit could allow the attacker to read, modify, or delete arbitrary data on an internal database, which could affect the availability of the device.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_data_center_network_manager | — | — |
| cisco | cisco_data_center_network_manager | — | — |
| cisco | cisco_data_center_network_manager | — | — |
| cisco | nexus_dashboard_fabric_controller | — | — |
| cisco | nexus_dashboard_fabric_controller | — | — |
| cisco | nexus_dashboard_fabric_controller | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for crafted requests sent to REST API endpoints of Cisco NDFC by authenticated users with read-only privileges, which may indicate SQL injection attempts ↗
- →Alert on anomalous SQL activity originating from the NDFC internal database, particularly unexpected read, modify, or delete operations that may indicate successful SQL injection exploitation ↗
- →Track Cisco bug ID CSCwi20825 for patch status and correlate with NDFC instances that have not yet applied the fix, as there are no workarounds available ↗
- ·Exploitation requires an authenticated attacker with at minimum read-only privileges; unauthenticated exploitation is not possible, so access control enforcement is a key mitigating factor ↗
- ·The vulnerability is rooted in insufficient input validation (CWE-89 SQL Injection); both the REST API endpoint and the web-based management interface are attack surfaces ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_cisco8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Nexus Dashboard Fabric Controller SQL Injection Vulnerability
vendor_cisco·2024-11-06·CVSS 8.8
CVE-2024-20536 [HIGH] CWE-89 Cisco Nexus Dashboard Fabric Controller SQL Injection Vulnerability
Cisco Nexus Dashboard Fabric Controller SQL Injection Vulnerability
A vulnerability in a REST API endpoint and web-based management interface of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, remote attacker with read-only privileges to execute arbitrary SQL commands on an affected device.
This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to a specific REST API endpoint or web-based management interface. A successful exploit could allow the attacker to read, modify, or delete arbitrary data on an internal database, which could affect the availability of the device.
Cisco has released software updates that address this vulnerability. There are no workarounds
Cisco
Cisco Nexus Dashboard Fabric Controller SQL Injection Vulnerability
vendor_cisco·CVSS 3.1
CVE-2024-20536 Cisco Nexus Dashboard Fabric Controller SQL Injection Vulnerability
CVE-2024-20536: Cisco Nexus Dashboard Fabric Controller SQL Injection Vulnerability
A vulnerability in a REST API endpoint and web-based management interface o f Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, remote attacker with read-only privileges to execute arbitrary SQL commands on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to a specific REST API endpoint or web-based management interface . A successful exploit could allow the attacker to read, modify, or delete arbitrary data on an internal database, which could affect the availability of the device. Cisco has released software updates that address this vulnerability. There are
GHSA
GHSA-5w27-pxmv-rgxx: A vulnerability in a REST API endpoint and web-based management interface of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticat
ghsa_unreviewed·2024-11-06
CVE-2024-20536 [HIGH] CWE-89 GHSA-5w27-pxmv-rgxx: A vulnerability in a REST API endpoint and web-based management interface of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticat
A vulnerability in a REST API endpoint and web-based management interface of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, remote attacker with read-only privileges to execute arbitrary SQL commands on an affected device.
This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to a specific REST API endpoint or web-based management interface. A successful exploit could allow the attacker to read, modify, or delete arbitrary data on an internal database, which could affect the availability of the device.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-11-06
Published