CVE-2024-20490: Cisco Nexus Dashboard Fabric Controller and Nexus Dashboard Orchestrator Information Disclosure Vulnerability
A vulnerability in a logging function of Cisco Nexus Dashboard Fabric Controller (NDFC) and Cisco Nexus Dashboard Orchestrator (NDO) could allow an attacker with access to a tech support file to view sensitive information. This vulnerability exists because HTTP proxy credentials could be recorded in an internal log that is stored in the tech support file. An attacker could exploit this vulnerability by accessing a tech support file that is generated from an affected system. A successful exploit could allow the attacker to view HTTP proxy server admin credentials in clear text that are configured on Nexus Dashboard to reach an external network. Note: Best practice is to store debug logs and tech support files safely and to share them only with trusted parties because they may contain sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20490?
CVE-2024-20490 is rated as a medium severity vulnerability due to the potential exposure of sensitive information.
How do I fix CVE-2024-20490?
To remediate CVE-2024-20490, you should update to the latest available version of the affected Cisco Nexus Dashboard products.
Who is affected by CVE-2024-20490?
CVE-2024-20490 affects users of Cisco Nexus Dashboard Fabric Controller, Cisco Nexus Dashboard Orchestrator, and Cisco Nexus Dashboard Insights within specific version ranges.
What types of attacks can exploit CVE-2024-20490?
An attacker with access to a tech support file could exploit CVE-2024-20490 to view HTTP proxy credentials and other sensitive information.
Is authentication required to access the vulnerable logging function in CVE-2024-20490?
Yes, the attacker must have access to the tech support file to exploit the vulnerability in CVE-2024-20490.