Description
A vulnerability in Cisco Nexus Dashboard could allow an authenticated, local attacker with valid rescue-user credentials to elevate privileges to root on an affected device.
This vulnerability is due to insufficient protections for a sensitive access token. An attacker could exploit this vulnerability by using this token to access resources within the device infrastructure. A successful exploit could allow an attacker to gain root access to the filesystem or hosted containers on an affected device.
This vulnerability is due to insufficient protections for a sensitive access token. An attacker could exploit this vulnerability by using this token to access resources within the device infrastructure. A successful exploit could allow an attacker to gain root access to the filesystem or hosted containers on an affected device.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-17997 | A vulnerability in Cisco Nexus Dashboard could allow an authenticated, local attacker with valid rescue-user credentials to elevate privileges to root on an affected device. This vulnerability is due to insufficient protections for a sensitive access token. An attacker could exploit this vulnerability by using this token to access resources within the device infrastructure. A successful exploit could allow an attacker to gain root access to the filesystem or hosted containers on an affected device. |
References
History
Wed, 07 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cisco
Cisco nexus Dashboard |
|
| Weaknesses | CWE-522 | |
| CPEs | cpe:2.3:a:cisco:nexus_dashboard:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cisco
Cisco nexus Dashboard |
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-08-27T13:39:11.505Z
Reserved: 2023-11-08T15:08:07.626Z
Link: CVE-2024-20282
Updated: 2024-08-01T21:59:41.778Z
Status : Analyzed
Published: 2024-04-03T17:15:47.950
Modified: 2025-05-07T14:48:42.433
Link: CVE-2024-20282
No data.
OpenCVE Enrichment
No data.
EUVD