A vulnerability in the Out-of-Band (OOB) Plug and Play (PnP) feature of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauthenticated, remote attacker to read arbitrary files.
This vulnerability is due to an unauthenticated provisioning web server. An attacker could exploit this vulnerability through direct web requests to the provisioning server. A successful exploit could allow the attacker to read sensitive files in the PnP container that could facilitate further attacks on the PnP infrastructure.
References
Configurations
Configuration 1 (hide)
|
History
07 May 2025, 16:08
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
References | () https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ndfc-dir-trav-SSn3AYDw - Vendor Advisory | |
First Time |
Cisco
Cisco nexus Dashboard Fabric Controller |
|
CWE | CWE-22 | |
CPE | cpe:2.3:a:cisco:nexus_dashboard_fabric_controller:12.1.3:*:*:*:*:*:*:* cpe:2.3:a:cisco:nexus_dashboard_fabric_controller:12.1.3b:*:*:*:*:*:*:* |
03 Apr 2024, 17:24
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-04-03 17:15
Updated : 2025-05-07 16:08
NVD link : CVE-2024-20348
Mitre link : CVE-2024-20348
JSON object : View
Products Affected
cisco
- nexus_dashboard_fabric_controller
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')