Database/Control plane, storage & DevOps
Cisco Nexus Dashboard Fabric Controller (path traversal to RCE via SCP): A low-privileged authenticated attacker
CVSS 8.8CVE-2024-20449Control plane, storage & DevOpscurated
Impact
A low-privileged authenticated attacker uploads a malicious file over SCP and executes code on the fabric controller.
Who can reach it
Authenticated low-privilege remote access to NDFC.
What to do
Upgrade NDFC per cisco-sa-ndfc-ptrce-BUSHLbp.
References
Related entries
- Cisco Nexus Dashboard Fabric Controller (SQL injection): A read-only NDFC user executes arbitrary SQL on the controllerCVE-2024-20536 · Cisco Nexus Dashboard Fabric Controller (SQL injection)High
- Jenkins: No origin validation on the CLI WebSocket endpointCVE-2024-23898 · JenkinsHigh
- MinIO: Access keys inherit the parent's `admin:*` actions, not just `s3:*`CVE-2024-24747 · MinIOHigh
- Dell OpenManage Integration for Windows Admin Center: authenticated remote code execution in the gateway pluginCVE-2024-24909 · Dell OpenManage Integration with Microsoft Windows Admin Center (gateway plugin)High
- A10 Thunder ADC (CsrRequestView): An authenticated attacker can inject a system-call payload through the CsrRequestViewCVE-2024-30368 · A10 Thunder ADC (CsrRequestView)High
- CyberPower PowerPanel MQTT message handling: An attacker with MQTT publish permissions can craft messagesCVE-2024-31856 · CyberPower PowerPanel MQTT message handlingHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.