A vulnerability in the SSL/TLS implementation of Cisco Nexus Dashboard Orchestrator (NDO) could allow an unauthenticated, remote attacker to intercept sensitive information from an affected device.  This vulnerability exists because the Cisco NDO Validate Peer Certificate site management feature validates the certificates for Cisco Application Policy Infrastructure Controller (APIC), Cisco Cloud Network Controller (CNC), and Cisco Nexus Dashboard only when a new site is added or an existing one is reregistered. An attacker could exploit this vulnerability by using machine-in-the-middle techniques to intercept the traffic between the affected device and Cisco NDO and then using a crafted certificate to impersonate the affected device. A successful exploit could allow the attacker to learn sensitive information during communications between these devices.
History

Tue, 08 Oct 2024 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco nexus Dashboard Orchestrator
CPEs cpe:2.3:a:cisco:nexus_dashboard_orchestrator:*:*:*:*:*:*:*:*
Vendors & Products Cisco
Cisco nexus Dashboard Orchestrator

Wed, 02 Oct 2024 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Oct 2024 17:00:00 +0000

Type Values Removed Values Added
Description A vulnerability in the SSL/TLS implementation of Cisco Nexus Dashboard Orchestrator (NDO) could allow an unauthenticated, remote attacker to intercept sensitive information from an affected device.  This vulnerability exists because the Cisco NDO Validate Peer Certificate site management feature validates the certificates for Cisco Application Policy Infrastructure Controller (APIC), Cisco Cloud Network Controller (CNC), and Cisco Nexus Dashboard only when a new site is added or an existing one is reregistered. An attacker could exploit this vulnerability by using machine-in-the-middle techniques to intercept the traffic between the affected device and Cisco NDO and then using a crafted certificate to impersonate the affected device. A successful exploit could allow the attacker to learn sensitive information during communications between these devices.
Title Cisco Nexus Dashboard Orchestrator SSL Certificate Validation Vulnerability
Weaknesses CWE-295
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published: 2024-10-02T16:52:55.860Z

Updated: 2024-10-02T19:02:55.769Z

Reserved: 2023-11-08T15:08:07.658Z

Link: CVE-2024-20385

cve-icon Vulnrichment

Updated: 2024-10-02T19:02:47.828Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-02T17:15:15.110

Modified: 2024-10-08T14:22:34.120

Link: CVE-2024-20385

cve-icon Redhat

No data.