← Back

CVE-2024-20449

nvd nist
Published: Oct 2, 2024Modified: Oct 8, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, remote attacker with low privileges to execute arbitrary code on an affected device. This vulnerability is due to improper path validation. An attacker could exploit this vulnerability by using the Secure Copy Protocol (SCP) to upload malicious code to an affected device using path traversal techniques. A successful exploit could allow the attacker to execute arbitrary code in a specific container with the privileges of root.

Affected (1)

1 product
Nexus Dashboard Fabric Controller
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 12.0.0 to 12.2.2

Timeline

No history available yet.