Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-20348

Опубликовано: 03 апр. 2024
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

A vulnerability in the Out-of-Band (OOB) Plug and Play (PnP) feature of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauthenticated, remote attacker to read arbitrary files.

This vulnerability is due to an unauthenticated provisioning web server. An attacker could exploit this vulnerability through direct web requests to the provisioning server. A successful exploit could allow the attacker to read sensitive files in the PnP container that could facilitate further attacks on the PnP infrastructure.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cisco:nexus_dashboard_fabric_controller:12.1.3:*:*:*:*:*:*:*
cpe:2.3:a:cisco:nexus_dashboard_fabric_controller:12.1.3b:*:*:*:*:*:*:*

EPSS

Процентиль: 70%
0.00645
Низкий

7.5 High

CVSS3

Дефекты

CWE-27
CWE-22

Связанные уязвимости

CVSS3: 7.5
github
почти 2 года назад

A vulnerability in the Out-of-Band (OOB) Plug and Play (PnP) feature of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauthenticated, remote attacker to read arbitrary files. This vulnerability is due to an unauthenticated provisioning web server. An attacker could exploit this vulnerability through direct web requests to the provisioning server. A successful exploit could allow the attacker to read sensitive files in the PnP container that could facilitate further attacks on the PnP infrastructure.

CVSS3: 7.5
fstec
почти 2 года назад

Уязвимость функции внеполосного подключения платформы управления сетевыми ресурсами Cisco Nexus Dashboard Fabric Controller (NDFC), позволяющая нарушителю прочитать произвольные файлы на сервере

EPSS

Процентиль: 70%
0.00645
Низкий

7.5 High

CVSS3

Дефекты

CWE-27
CWE-22