Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-20441

Опубликовано: 02 окт. 2024
Источник: nvd
CVSS3: 5.7
CVSS3: 6.5
EPSS Низкий

Описание

A vulnerability in a specific REST API endpoint of Cisco NDFC could allow an authenticated, low-privileged, remote attacker to learn sensitive information on an affected device.

This vulnerability is due to insufficient authorization controls on the affected REST API endpoint. An attacker could exploit this vulnerability by sending crafted API requests to the affected endpoint. A successful exploit could allow the attacker to download config only or full backup files and learn sensitive configuration information. This vulnerability only affects a specific REST API endpoint and does not affect the web-based management interface.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cisco:nexus_dashboard:*:*:*:*:*:*:*:*
Версия до 3.2\(1e\) (исключая)
cpe:2.3:a:cisco:nexus_dashboard_fabric_controller:*:*:*:*:*:*:*:*
Версия от 12.0.0 (включая) до 12.2.2 (исключая)

EPSS

Процентиль: 42%
0.00197
Низкий

5.7 Medium

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-285
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 5.7
github
больше 1 года назад

A vulnerability in a specific REST API endpoint of Cisco NDFC could allow an authenticated, low-privileged, remote attacker to learn sensitive information on an affected device. This vulnerability is due to insufficient authorization controls on the affected REST API endpoint. An attacker could exploit this vulnerability by sending crafted API requests to the affected endpoint. A successful exploit could allow the attacker to download config only or full backup files and learn sensitive configuration information. This vulnerability only affects a specific REST API endpoint and does not affect the web-based management interface.

CVSS3: 6.5
fstec
больше 1 года назад

Уязвимость реализации прикладного программного интерфейса платформы управления сетевыми ресурсами Cisco Nexus Dashboard Fabric Controller (NDFC), связанная с неправильной авторизацией, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 42%
0.00197
Низкий

5.7 Medium

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-285
NVD-CWE-noinfo