CVE-2024-20490: Cisco Nexus Dashboard Fabric Controller and Nexus Dashboard Orchestrator Information Disclosure Vulnerability

Published Oct 2, 2024
·
Updated

A vulnerability in a logging function of Cisco Nexus Dashboard Fabric Controller (NDFC) and Cisco Nexus Dashboard Orchestrator (NDO) could allow an attacker with access to a tech support file to view sensitive information. This vulnerability exists because HTTP proxy credentials could be recorded in an internal log that is stored in the tech support file. An attacker could exploit this vulnerability by accessing a tech support file that is generated from an affected system. A successful exploit could allow the attacker to view HTTP proxy server admin credentials in clear text that are configured on Nexus Dashboard to reach an external network. Note: Best practice is to store debug logs and tech support files safely and to share them only with trusted parties because they may contain sensitive information.

Affected Software

5 affected components
Cisco Nexus Dashboard Fabric Controller>=12.1.0<12.2.2.241
Cisco Nexus Dashboard Insights<6.4.0
Cisco Nexus Dashboard Insights>=6.5.0<6.5.1.32
Cisco Nexus Dashboard Orchestrator<4.2\(3o\)
Cisco Nexus Dashboard Orchestrator>=4.4.0<4.4.1.1012

Event History

Oct 2, 2024
CVE Published
via MITRE·04:55 PM
Data Sourced
via MITRE·04:55 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-20490?

CVE-2024-20490 is rated as a medium severity vulnerability due to the potential exposure of sensitive information.

2

How do I fix CVE-2024-20490?

To remediate CVE-2024-20490, you should update to the latest available version of the affected Cisco Nexus Dashboard products.

3

Who is affected by CVE-2024-20490?

CVE-2024-20490 affects users of Cisco Nexus Dashboard Fabric Controller, Cisco Nexus Dashboard Orchestrator, and Cisco Nexus Dashboard Insights within specific version ranges.

4

What types of attacks can exploit CVE-2024-20490?

An attacker with access to a tech support file could exploit CVE-2024-20490 to view HTTP proxy credentials and other sensitive information.

5

Is authentication required to access the vulnerable logging function in CVE-2024-20490?

Yes, the attacker must have access to the tech support file to exploit the vulnerability in CVE-2024-20490.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203