Cisco Nexus Dashboard Fabric Controller Vulnerability Could Lead to Command Injection and Denial of Service Attacks
CVE-2024-20444
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 2 October 2024
Summary
A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC), formerly Cisco Data Center Network Manager (DCNM), could allow an authenticated, remote attacker with network-admin privileges to perform a command injection attack against an affected device. This vulnerability is due to insufficient validation of command arguments. An attacker could exploit this vulnerability by submitting crafted command arguments to a specific REST API endpoint. A successful exploit could allow the attacker to overwrite sensitive files or crash a specific container, which would restart on its own, causing a low-impact denial of service (DoS) condition.
Affected Version(s)
Cisco Data Center Network Manager 11.2(1)
Cisco Data Center Network Manager 7.0(2)
Cisco Data Center Network Manager 10.3(2)IPFM
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved