SB2024100333 - Multiple vulnerabilities in Cisco Nexus Dashboard Fabric Controller (NDFC), Cisco Nexus Dashboard Insights and Cisco Nexus Dashboard Orchestrator (NDO)
Published: October 3, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Information disclosure (CVE-ID: CVE-2024-20490)
The vulnerability allows a local attacker to gain access to potentially sensitive information.
The vulnerability exists due to HTTP proxy credentials can be recorded in an internal log that is stored in the tech support file. A local attacker can gain unauthorized access to sensitive information on the system.
2) Information disclosure (CVE-ID: CVE-2024-20491)
The vulnerability allows a local attacker to gain access to potentially sensitive information.
The vulnerability exists due to remote controller credentials are recorded in an internal log that is stored in the tech support file. A local attacker can view remote controller admin credentials in clear text.
Remediation
Install update from vendor's website.