Out-of-Band Plug and Play Vulnerability in Cisco Nexus Dashboard Fabric Controller
CVE-2024-20348

Currently unrated

Key Information:

Vendor
Cisco
Vendor
CVE Published:
3 April 2024

Badges

๐Ÿ’ฐ Ransomware๐Ÿ‘พ Exploit Exists๐Ÿ“ฐ News Worthy

Summary

A vulnerability exists in the Out-of-Band (OOB) Plug and Play (PnP) feature of Cisco Nexus Dashboard Fabric Controller that may allow an unauthenticated and remote attacker to read arbitrary files from the system. This issue stems from the presence of an unauthenticated provisioning web server, which can be exploited through direct web requests. Successful exploitation may grant the attacker access to sensitive files within the PnP container, potentially leading to further attacks against the PnP infrastructure. This highlights the need for immediate attention to the security configuration of the affected product.

News Articles

Cisco Nexus Dashboard Vulnerability Let Attackers Read Arbitrary Files

Cisco Nexus Dashboard Fabric Controller is a network management platform for all the NX-OS enabled devices which enables data center operation

10 months ago

References

Timeline

  • ๐Ÿ’ฐ

    Used in Ransomware

  • ๐Ÿ‘พ

    Exploit known to exist

  • ๐Ÿ“ฐ

    First article discovered by CybersecurityNews

  • Vulnerability published

.