SB2024100333 - Multiple vulnerabilities in Cisco Nexus Dashboard Fabric Controller (NDFC), Cisco Nexus Dashboard Insights and Cisco Nexus Dashboard Orchestrator (NDO)



SB2024100333 - Multiple vulnerabilities in Cisco Nexus Dashboard Fabric Controller (NDFC), Cisco Nexus Dashboard Insights and Cisco Nexus Dashboard Orchestrator (NDO)

Published: October 3, 2024

Security Bulletin ID SB2024100333
Severity
Low
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Local access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Information disclosure (CVE-ID: CVE-2024-20490)

The vulnerability allows a local attacker to gain access to potentially sensitive information.

The vulnerability exists due to HTTP proxy credentials can be recorded in an internal log that is stored in the tech support file. A local attacker can gain unauthorized access to sensitive information on the system.


2) Information disclosure (CVE-ID: CVE-2024-20491)

The vulnerability allows a local attacker to gain access to potentially sensitive information.

The vulnerability exists due to remote controller credentials are recorded in an internal log that is stored in the tech support file. A local attacker can view remote controller admin credentials in clear text.


Remediation

Install update from vendor's website.