Description

A vulnerability in a REST API endpoint and web-based management interface of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, remote attacker with read-only privileges to execute arbitrary SQL commands on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to a specific REST API endpoint or web-based management interface. A successful exploit could allow the attacker to read, modify, or delete arbitrary data on an internal database, which could affect the availability of the device. 

INFO

Published Date :

2024-11-06T16:31:38.476Z

Last Modified :

2024-11-09T04:55:53.544Z

Source :

cisco
AFFECTED PRODUCTS

The following products are affected by CVE-2024-20536 vulnerability.

Vendors Products
Cisco
  • Data Center Network Manager
  • Nexus Dashboard Fabric Controller
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2024-20536.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact