VDB
CVE-2024-20441
CVE-2024-20441
PUBLISHED
In Cisco Nexus Dashboard und dem Nexus Dashboard Fabric Controller existieren mehrere Schwachstellen. Diese bestehen unter anderem aufgrund von unzureichenden Überprüfungen von Autorisierungen und Befehlsargumenten, sowie unsachgemäßer Speicherung von Informationen. Ein Angreifer kann diese Schwachstellen ausnutzen, um Informationen offenzulegen, Sicherheitsmaßnahmen zu umgehen und beliebigen Code, im schlimmsten Fall mit Administratorrechten, zur Ausführung zu bringen. Zur Ausnutzung einiger dieser Schwachstellen ist eine Authentisierung erforderlich.
EPSS 0.27% · 50.6th percentile
Risk Scores
EPSS Score
0.27%
50.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Cisco Nexus Dashboard <12.2.2 |
Exploit Intelligence
- cisco-sa-ndhs-uaapi-Jh4V6zpN (circl)
Timeline
- Oct 2, 2024 CVE Published
- Oct 2, 2024 CVE Updated
- Oct 3, 2024 EPSS Score
- Oct 4, 2024 Coalition ESS Score
- Oct 15, 2024 Coalition ESS Score
- Oct 16, 2024 Coalition ESS Score
- Oct 22, 2024 EPSS Score
- Nov 10, 2024 EPSS Score
- Nov 29, 2024 EPSS Score
- Dec 19, 2024 EPSS Score
- Jan 7, 2025 EPSS Score
- Jan 26, 2025 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-3072.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-3072 advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ndfc-cmdinj-UvYZrKfr advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ndfc-raci-T46k3jnN advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ndfc-cidv-XvyX2wLj advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ndfc-ptrce-BUSHLbp advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ndhs-uaapi-Jh4V6zpN advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ndhs-idv-Bk8VqEDc advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ndo-tlsvld-FdUF3cpw advisory