Логотип exploitDog
bind:CVE-2024-20302
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-20302

Количество 3

Количество 3

nvd логотип

CVE-2024-20302

почти 2 года назад

A vulnerability in the tenant security implementation of Cisco Nexus Dashboard Orchestrator (NDO) could allow an authenticated, remote attacker to modify or delete tenant templates on an affected system. This vulnerability is due to improper access controls within tenant security. An attacker who is using a valid user account with write privileges and either a Site Manager or Tenant Manager role could exploit this vulnerability. A successful exploit could allow the attacker to modify or delete tenant templates under non-associated tenants, which could disrupt network traffic.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-5m8h-3c7v-787m

почти 2 года назад

A vulnerability in the tenant security implementation of Cisco Nexus Dashboard Orchestrator (NDO) could allow an authenticated, remote attacker to modify or delete tenant templates on an affected system. This vulnerability is due to improper access controls within tenant security. An attacker who is using a valid user account with write privileges and either a Site Manager or Tenant Manager role could exploit this vulnerability. A successful exploit could allow the attacker to modify or delete tenant templates under non-associated tenants, which could disrupt network traffic.

CVSS3: 5.4
EPSS: Низкий
fstec логотип

BDU:2024-04196

почти 2 года назад

Уязвимость средства управления сетью и политиками дата-центров Cisco Nexus Dashboard Orchestrator (ранее Cisco Multi-Site Orchestrator), связанная с недостатками разграничения доступ, позволяющая нарушителю получить доступ на чтение, изменение или удаление данных

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-20302

A vulnerability in the tenant security implementation of Cisco Nexus Dashboard Orchestrator (NDO) could allow an authenticated, remote attacker to modify or delete tenant templates on an affected system. This vulnerability is due to improper access controls within tenant security. An attacker who is using a valid user account with write privileges and either a Site Manager or Tenant Manager role could exploit this vulnerability. A successful exploit could allow the attacker to modify or delete tenant templates under non-associated tenants, which could disrupt network traffic.

CVSS3: 5.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-5m8h-3c7v-787m

A vulnerability in the tenant security implementation of Cisco Nexus Dashboard Orchestrator (NDO) could allow an authenticated, remote attacker to modify or delete tenant templates on an affected system. This vulnerability is due to improper access controls within tenant security. An attacker who is using a valid user account with write privileges and either a Site Manager or Tenant Manager role could exploit this vulnerability. A successful exploit could allow the attacker to modify or delete tenant templates under non-associated tenants, which could disrupt network traffic.

CVSS3: 5.4
0%
Низкий
почти 2 года назад
fstec логотип
BDU:2024-04196

Уязвимость средства управления сетью и политиками дата-центров Cisco Nexus Dashboard Orchestrator (ранее Cisco Multi-Site Orchestrator), связанная с недостатками разграничения доступ, позволяющая нарушителю получить доступ на чтение, изменение или удаление данных

CVSS3: 5.4
0%
Низкий
почти 2 года назад

Уязвимостей на страницу