CVE-2024-20441

Oct. 2, 2024, 5:15 p.m.

Received
CVE has been recently published to the CVE List and has been received by the NVD.

Products

Cisco NDFC

Source

ykramarz@cisco.com

Tags

CVE-2024-20441 details

Published : Oct. 2, 2024, 5:15 p.m.
Last Modified : Oct. 2, 2024, 5:15 p.m.

Description

A vulnerability in a specific REST API endpoint of Cisco NDFC could allow an authenticated, low-privileged, remote attacker to learn sensitive information on an affected device. This vulnerability is due to insufficient authorization controls on the affected REST API endpoint. An attacker could exploit this vulnerability by sending crafted API requests to the affected endpoint. A successful exploit could allow the attacker to download config only or full backup files and learn sensitive configuration information. This vulnerability only affects a specific REST API endpoint and does not affect the web-based management interface.

CVSS Score

1 2 3 4 5.7 6 7 8 9 10

Weakness

Weakness Name Description
CWE-285 Improper Authorization The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

CVSS Data

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

Base Score

5.7

Exploitability Score

2.1

Impact Score

3.6

Base Severity

MEDIUM

This website uses the NVD API, but is not approved or certified by it.