A vulnerability in the REST API endpoints of Cisco Nexus Dashboard could allow an authenticated, low-privileged, remote attacker to perform limited Administrator actions on an affected device. This vulnerability is due to insufficient authorization controls on some REST API endpoints. An attacker could exploit this vulnerability by sending crafted API requests to an affected endpoint. A successful exploit could allow the attacker to perform limited Administrator functions such as viewing portions of the web UI, generating config only or full backup files, and deleting tech support files. This vulnerability only affects a subset of REST API endpoints and does not affect the web-based management interface.
History

Mon, 07 Oct 2024 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco nexus Dashboard
Cisco nexus Dashboard Fabric Controller
CPEs cpe:2.3:a:cisco:nexus_dashboard:*:*:*:*:*:*:*:*
cpe:2.3:a:cisco:nexus_dashboard_fabric_controller:*:*:*:*:*:*:*:*
Vendors & Products Cisco
Cisco nexus Dashboard
Cisco nexus Dashboard Fabric Controller

Wed, 02 Oct 2024 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Oct 2024 17:00:00 +0000

Type Values Removed Values Added
Description A vulnerability in the REST API endpoints of Cisco Nexus Dashboard could allow an authenticated, low-privileged, remote attacker to perform limited Administrator actions on an affected device. This vulnerability is due to insufficient authorization controls on some REST API endpoints. An attacker could exploit this vulnerability by sending crafted API requests to an affected endpoint. A successful exploit could allow the attacker to perform limited Administrator functions such as viewing portions of the web UI, generating config only or full backup files, and deleting tech support files. This vulnerability only affects a subset of REST API endpoints and does not affect the web-based management interface.
Title Cisco Nexus Dashboard Unauthorized API Endpoints Vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published: 2024-10-02T16:53:41.383Z

Updated: 2024-10-02T19:28:58.418Z

Reserved: 2023-11-08T15:08:07.676Z

Link: CVE-2024-20442

cve-icon Vulnrichment

Updated: 2024-10-02T19:28:51.107Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-02T17:15:16.177

Modified: 2024-10-07T20:11:48.687

Link: CVE-2024-20442

cve-icon Redhat

No data.