CVE-2024-20536: Cisco Nexus Dashboard Fabric Controller SQL Injection Vulnerability
A vulnerability in a REST API endpoint and web-based management interface of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, remote attacker with read-only privileges to execute arbitrary SQL commands on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to a specific REST API endpoint or web-based management interface. A successful exploit could allow the attacker to read, modify, or delete arbitrary data on an internal database, which could affect the availability of the device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20536?
CVE-2024-20536 has been classified as a high severity vulnerability due to its potential for remote SQL command execution.
How do I fix CVE-2024-20536?
To fix CVE-2024-20536, update your Cisco Nexus Dashboard Fabric Controller to the latest version as recommended by Cisco.
Who is affected by CVE-2024-20536?
CVE-2024-20536 affects devices running Cisco Nexus Dashboard Fabric Controller with access to its REST API and web-based management interface.
What type of attack is possible with CVE-2024-20536?
CVE-2024-20536 allows an authenticated, remote attacker with read-only privileges to execute arbitrary SQL commands.
When was CVE-2024-20536 disclosed?
CVE-2024-20536 was disclosed recently and users are advised to apply the necessary updates immediately.