CVE-2024-20282: Medium severity cisco nexus dashboard software vulnerability
A vulnerability in Cisco Nexus Dashboard could allow an authenticated, local attacker with valid rescue-user credentials to elevate privileges to root on an affected device. This vulnerability is due to insufficient protections for a sensitive access token. An attacker could exploit this vulnerability by using this token to access resources within the device infrastructure. A successful exploit could allow an attacker to gain root access to the filesystem or hosted containers on an affected device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20282?
The severity of CVE-2024-20282 is rated as high due to the potential for privilege escalation to root by an authenticated local attacker.
How do I fix CVE-2024-20282?
To fix CVE-2024-20282, update your Cisco Nexus Dashboard to the latest version provided by Cisco that addresses this vulnerability.
What type of attack does CVE-2024-20282 enable?
CVE-2024-20282 enables an authenticated local attacker to elevate privileges to root on an affected device.
Who is affected by CVE-2024-20282?
CVE-2024-20282 affects users of Cisco Nexus Dashboard who have rescue-user credentials.
What causes the vulnerability CVE-2024-20282?
CVE-2024-20282 is caused by insufficient protections for a sensitive access token within Cisco Nexus Dashboard.