Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m7q5-x69w-qc6v

Опубликовано: 03 апр. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

A vulnerability in the Out-of-Band (OOB) Plug and Play (PnP) feature of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauthenticated, remote attacker to read arbitrary files.

This vulnerability is due to an unauthenticated provisioning web server. An attacker could exploit this vulnerability through direct web requests to the provisioning server. A successful exploit could allow the attacker to read sensitive files in the PnP container that could facilitate further attacks on the PnP infrastructure.

A vulnerability in the Out-of-Band (OOB) Plug and Play (PnP) feature of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauthenticated, remote attacker to read arbitrary files.

This vulnerability is due to an unauthenticated provisioning web server. An attacker could exploit this vulnerability through direct web requests to the provisioning server. A successful exploit could allow the attacker to read sensitive files in the PnP container that could facilitate further attacks on the PnP infrastructure.

EPSS

Процентиль: 70%
0.00645
Низкий

7.5 High

CVSS3

Дефекты

CWE-22
CWE-27

Связанные уязвимости

CVSS3: 7.5
nvd
почти 2 года назад

A vulnerability in the Out-of-Band (OOB) Plug and Play (PnP) feature of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauthenticated, remote attacker to read arbitrary files. This vulnerability is due to an unauthenticated provisioning web server. An attacker could exploit this vulnerability through direct web requests to the provisioning server. A successful exploit could allow the attacker to read sensitive files in the PnP container that could facilitate further attacks on the PnP infrastructure.

CVSS3: 7.5
fstec
почти 2 года назад

Уязвимость функции внеполосного подключения платформы управления сетевыми ресурсами Cisco Nexus Dashboard Fabric Controller (NDFC), позволяющая нарушителю прочитать произвольные файлы на сервере

EPSS

Процентиль: 70%
0.00645
Низкий

7.5 High

CVSS3

Дефекты

CWE-22
CWE-27