First published: Wed Apr 03 2024(Updated: )
A vulnerability in the Out-of-Band (OOB) Plug and Play (PnP) feature of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauthenticated, remote attacker to read arbitrary files. This vulnerability is due to an unauthenticated provisioning web server. An attacker could exploit this vulnerability through direct web requests to the provisioning server. A successful exploit could allow the attacker to read sensitive files in the PnP container that could facilitate further attacks on the PnP infrastructure.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Nexus Dashboard Fabric Controller |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2024-20348 is considered a high severity vulnerability due to its potential for unauthenticated remote access to sensitive files.
To fix CVE-2024-20348, users should update their Cisco Nexus Dashboard Fabric Controller to the latest version as per the security advisories provided by Cisco.
CVE-2024-20348 affects any installation of the Cisco Nexus Dashboard Fabric Controller that utilizes the Out-of-Band Plug and Play feature.
Yes, CVE-2024-20348 can be exploited by an unauthenticated, remote attacker.
CVE-2024-20348 facilitates arbitrary file reading attacks due to an unauthenticated provisioning web server.