We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-20448

Cisco Nexus Dashboard Fabric Controller Credential Information Disclosure Vulnerability



Description

A vulnerability in the Cisco Nexus Dashboard Fabric Controller (NDFC) software, formerly Cisco Data Center Network Manager (DCNM), could allow an attacker with access to a backup file to view sensitive information. This vulnerability is due to the improper storage of sensitive information within config only and full backup files. An attacker could exploit this vulnerability by parsing the contents of a backup file that is generated from an affected device. A successful exploit could allow the attacker to access sensitive information, including NDFC-connected device credentials, the NDFC site manager private key, and the scheduled backup file encryption key.

Reserved 2023-11-08 | Published 2024-10-02 | Updated 2024-10-02 | Assigner cisco


MEDIUM: 6.3CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N

Problem types

Cleartext Storage in a File or on Disk

Product status

Default status
unknown

11.2(1)
affected

7.0(2)
affected

10.3(2)IPFM
affected

10.1(1)
affected

7.2(3)
affected

7.2(2)
affected

7.2(1)
affected

11.0(1)
affected

10.4(1)
affected

10.2(1)
affected

7.2(2a)
affected

10.1(2)
affected

7.1(1)
affected

12.1(1)
affected

11.1(1)
affected

10.3(1)
affected

10.3(1)R(1)
affected

7.0(1)
affected

10.0(1)
affected

7.1(2)
affected

11.4(1)
affected

10.4(2)
affected

11.3(1)
affected

11.5(1)
affected

11.5(2)
affected

11.5(3)
affected

12.0.1a
affected

11.5(3a)
affected

12.0.2d
affected

12.0.2f
affected

11.5(4)
affected

12.1.1
affected

12.1.1e
affected

12.1.1p
affected

12.1.2e
affected

12.1.2p
affected

12.1.3b
affected

12.2.1
affected

References

sec.cloudapps.cisco.com/...isory/cisco-sa-ndfc-cidv-XvyX2wLj (cisco-sa-ndfc-cidv-XvyX2wLj)

cve.org (CVE-2024-20448)

nvd.nist.gov (CVE-2024-20448)

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-20448

Support options

Helpdesk Chat, Email, Knowledgebase
Telegram Chat
Subscribe to our newsletter to learn more about our work.