Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-20444

Опубликовано: 02 окт. 2024
Источник: nvd
CVSS3: 5.5
EPSS Низкий

Описание

A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC), formerly Cisco Data Center Network Manager (DCNM), could allow an authenticated, remote attacker with network-admin privileges to perform a command injection attack against an affected device.   This vulnerability is due to insufficient validation of command arguments. An attacker could exploit this vulnerability by submitting crafted command arguments to a specific REST API endpoint. A successful exploit could allow the attacker to overwrite sensitive files or crash a specific container, which would restart on its own, causing a low-impact denial of service (DoS) condition.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cisco:nexus_dashboard_fabric_controller:*:*:*:*:*:*:*:*
Версия до 12.2.2 (исключая)

EPSS

Процентиль: 50%
0.0027
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-88
CWE-88

Связанные уязвимости

CVSS3: 5.5
github
больше 1 года назад

A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC), formerly Cisco Data Center Network Manager (DCNM), could allow an authenticated, remote attacker with network-admin privileges to perform a command injection attack against an affected device.   This vulnerability is due to insufficient validation of command arguments. An attacker could exploit this vulnerability by submitting crafted command arguments to a specific REST API endpoint. A successful exploit could allow the attacker to overwrite sensitive files or crash a specific container, which would restart on its own, causing a low-impact denial of service (DoS) condition.

CVSS3: 5.5
fstec
больше 1 года назад

Уязвимость реализации прикладного программного интерфейса платформы управления сетевыми ресурсами Cisco Nexus Dashboard Fabric Controller (NDFC), связанная с внедрением или модификацией аргументов, позволяющая нарушителю вызвать отказ в обслуживании.

EPSS

Процентиль: 50%
0.0027
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-88
CWE-88