CVE-2024-20444: Cisco Nexus Dashboard Fabric Controller REST API Command Injection Vulnerability
A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC), formerly Cisco Data Center Network Manager (DCNM), could allow an authenticated, remote attacker with network-admin privileges to perform a command injection attack against an affected device. This vulnerability is due to insufficient validation of command arguments. An attacker could exploit this vulnerability by submitting crafted command arguments to a specific REST API endpoint. A successful exploit could allow the attacker to overwrite sensitive files or crash a specific container, which would restart on its own, causing a low-impact denial of service (DoS) condition.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20444?
CVE-2024-20444 has been classified with a high severity level due to its potential for command injection attacks.
How do I fix CVE-2024-20444?
To fix CVE-2024-20444, users should update their Cisco Nexus Dashboard Fabric Controller to version 12.2.2 or later.
Who is affected by CVE-2024-20444?
CVE-2024-20444 affects Cisco Nexus Dashboard Fabric Controller instances running versions prior to 12.2.2.
What type of attack does CVE-2024-20444 enable?
CVE-2024-20444 enables authenticated remote attackers to perform command injection attacks on affected devices.
What privileges are required to exploit CVE-2024-20444?
Exploitation of CVE-2024-20444 requires the attacker to have network-admin privileges.