Out-of-Band Plug and Play Vulnerability in Cisco Nexus Dashboard Fabric Controller
CVE-2024-20348

7.5HIGH

Key Information:

Vendor

Cisco

Vendor
CVE Published:
3 April 2024

Badges

πŸ’° RansomwareπŸ‘Ύ Exploit ExistsπŸ“° News Worthy

What is CVE-2024-20348?

A vulnerability exists in the Out-of-Band (OOB) Plug and Play (PnP) feature of Cisco Nexus Dashboard Fabric Controller that may allow an unauthenticated and remote attacker to read arbitrary files from the system. This issue stems from the presence of an unauthenticated provisioning web server, which can be exploited through direct web requests. Successful exploitation may grant the attacker access to sensitive files within the PnP container, potentially leading to further attacks against the PnP infrastructure. This highlights the need for immediate attention to the security configuration of the affected product.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

News Articles

Cisco Nexus Dashboard Vulnerability Let Attackers Read Arbitrary Files

Cisco Nexus Dashboard Fabric Controller is a network management platform for all the NX-OS enabled devices which enables data center operation

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • πŸ’°

    Used in Ransomware

  • πŸ‘Ύ

    Exploit known to exist

  • πŸ“°

    First article discovered by CybersecurityNews

  • Vulnerability published

.