Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rvwm-3c9j-xm8h

Опубликовано: 02 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC), formerly Cisco Data Center Network Manager (DCNM), could allow an authenticated, remote attacker with network-admin privileges to perform a command injection attack against an affected device.   This vulnerability is due to insufficient validation of command arguments. An attacker could exploit this vulnerability by submitting crafted command arguments to a specific REST API endpoint. A successful exploit could allow the attacker to overwrite sensitive files or crash a specific container, which would restart on its own, causing a low-impact denial of service (DoS) condition.

A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC), formerly Cisco Data Center Network Manager (DCNM), could allow an authenticated, remote attacker with network-admin privileges to perform a command injection attack against an affected device.   This vulnerability is due to insufficient validation of command arguments. An attacker could exploit this vulnerability by submitting crafted command arguments to a specific REST API endpoint. A successful exploit could allow the attacker to overwrite sensitive files or crash a specific container, which would restart on its own, causing a low-impact denial of service (DoS) condition.

EPSS

Процентиль: 50%
0.0027
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-88

Связанные уязвимости

CVSS3: 5.5
nvd
больше 1 года назад

A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC), formerly Cisco Data Center Network Manager (DCNM), could allow an authenticated, remote attacker with network-admin privileges to perform a command injection attack against an affected device.   This vulnerability is due to insufficient validation of command arguments. An attacker could exploit this vulnerability by submitting crafted command arguments to a specific REST API endpoint. A successful exploit could allow the attacker to overwrite sensitive files or crash a specific container, which would restart on its own, causing a low-impact denial of service (DoS) condition.

CVSS3: 5.5
fstec
больше 1 года назад

Уязвимость реализации прикладного программного интерфейса платформы управления сетевыми ресурсами Cisco Nexus Dashboard Fabric Controller (NDFC), связанная с внедрением или модификацией аргументов, позволяющая нарушителю вызвать отказ в обслуживании.

EPSS

Процентиль: 50%
0.0027
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-88