Database/Control plane, storage & DevOps
Cisco Nexus Dashboard Fabric Controller (SQL injection): A read-only NDFC user executes arbitrary SQL on the controller
CVSS 8.8CVE-2024-20536Control plane, storage & DevOpscurated
Impact
A read-only NDFC user executes arbitrary SQL on the controller database - which holds the fabric's configuration and credentials.
Who can reach it
Authenticated read-only remote access to NDFC.
What to do
Upgrade NDFC per cisco-sa-ndfc-sqli-CyPPAxrL.
References
Related entries
- Jenkins: No origin validation on the CLI WebSocket endpointCVE-2024-23898 · JenkinsHigh
- MinIO: Access keys inherit the parent's `admin:*` actions, not just `s3:*`CVE-2024-24747 · MinIOHigh
- Dell OpenManage Integration for Windows Admin Center: authenticated remote code execution in the gateway pluginCVE-2024-24909 · Dell OpenManage Integration with Microsoft Windows Admin Center (gateway plugin)High
- A10 Thunder ADC (CsrRequestView): An authenticated attacker can inject a system-call payload through the CsrRequestViewCVE-2024-30368 · A10 Thunder ADC (CsrRequestView)High
- CyberPower PowerPanel MQTT message handling: An attacker with MQTT publish permissions can craft messagesCVE-2024-31856 · CyberPower PowerPanel MQTT message handlingHigh
- AMD Graphics Driver - crafted pointer leading to arbitrary code execution: Improper input validation in the AMDCVE-2024-36324 · AMD Graphics Driver - crafted pointer leading to arbitrary code executionHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.