Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-20913

Опубликовано: 22 июл. 2022
Источник: nvd
CVSS3: 4.9
CVSS3: 6.5
EPSS Низкий

Описание

A vulnerability in Cisco Nexus Dashboard could allow an authenticated, remote attacker to write arbitrary files on an affected device. This vulnerability is due to insufficient input validation in the web-based management interface of Cisco Nexus Dashboard. An attacker with Administrator credentials could exploit this vulnerability by uploading a crafted file. A successful exploit could allow the attacker to overwrite arbitrary files on an affected device.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cisco:nexus_dashboard:*:*:*:*:*:*:*:*
Версия от 2.0 (включая) до 2.2\(1e\) (исключая)

EPSS

Процентиль: 32%
0.00125
Низкий

4.9 Medium

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-23
CWE-20

Связанные уязвимости

CVSS3: 6.5
github
больше 3 лет назад

A vulnerability in Cisco Nexus Dashboard could allow an authenticated, remote attacker to write arbitrary files on an affected device. This vulnerability is due to insufficient input validation in the web-based management interface of Cisco Nexus Dashboard. An attacker with Administrator credentials could exploit this vulnerability by uploading a crafted file. A successful exploit could allow the attacker to overwrite arbitrary files on an affected device.

CVSS3: 4.9
fstec
больше 3 лет назад

Уязвимость интерфейса командной строки (CLI) платформы аналитики и автоматизации работы с многооблачными сетями дата-центров Cisco Nexus Dashboard, позволяющая нарушителю перезаписать произвольные файлы

EPSS

Процентиль: 32%
0.00125
Низкий

4.9 Medium

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-23
CWE-20