CVE-2024-20491: Cisco Nexus Dashboard Insights Information Disclosure Vulnerability

Published Oct 2, 2024
·
Updated

A vulnerability in a logging function of Cisco Nexus Dashboard Insights could allow an attacker with access to a tech support file to view sensitive information. This vulnerability exists because remote controller credentials are recorded in an internal log that is stored in the tech support file. An attacker could exploit this vulnerability by accessing a tech support file that is generated from an affected system. A successful exploit could allow the attacker to view remote controller admin credentials in clear text. Note: Best practice is to store debug logs and tech support files safely and to share them only with trusted parties because they may contain sensitive information.

Affected Software

5 affected components
Cisco Nexus Dashboard Fabric Controller>=12.1.0<12.2.2.241
Cisco Nexus Dashboard Insights<6.4.0
Cisco Nexus Dashboard Insights>=6.5.0<6.5.1.32
Cisco Nexus Dashboard Orchestrator<4.2\(3o\)
Cisco Nexus Dashboard Orchestrator>=4.4.0<4.4.1.1012

Event History

Oct 2, 2024
CVE Published
via MITRE·04:55 PM
Data Sourced
via MITRE·04:55 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-20491?

CVE-2024-20491 is rated as a high severity vulnerability due to the potential exposure of sensitive information.

2

How do I fix CVE-2024-20491?

To mitigate CVE-2024-20491, you should upgrade to the latest versions of the affected Cisco Nexus Dashboard software as recommended by Cisco.

3

Who is affected by CVE-2024-20491?

CVE-2024-20491 affects users of Cisco Nexus Dashboard Insights, Nexus Dashboard Fabric Controller, and Nexus Dashboard Orchestrator running specific versions.

4

What kind of information could be exposed due to CVE-2024-20491?

CVE-2024-20491 could expose sensitive remote controller credentials that are improperly logged.

5

Is there a workaround for CVE-2024-20491?

There are currently no documented workarounds for CVE-2024-20491, and updating to a fixed version is necessary to resolve the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203