📦 Nexus Dashboard Fabric Controller

by Cisco

🔍 What is Nexus Dashboard Fabric Controller?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-20432

CRITICAL CVSS 9.9 Oct 2, 2024

An authenticated low-privileged attacker can execute arbitrary CLI commands with network-admin privileges on Cisco NDFC-managed devices via command injection in REST API or web UI. This affects Cisco ...

CVE-2024-20536

HIGH CVSS 8.8 Nov 6, 2024

This SQL injection vulnerability in Cisco Nexus Dashboard Fabric Controller allows authenticated users with read-only privileges to execute arbitrary SQL commands through REST API or web interface. At...

CVE-2024-20449

HIGH CVSS 8.8 Oct 2, 2024

This vulnerability allows authenticated remote attackers with low privileges to execute arbitrary code as root on Cisco Nexus Dashboard Fabric Controller devices. Attackers exploit improper path valid...

CVE-2024-20348

HIGH CVSS 7.5 Apr 3, 2024

This vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC) allows unauthenticated remote attackers to read arbitrary files via the Out-of-Band Plug and Play provisioning web server. It affec...

CVE-2024-20477

MEDIUM CVSS 5.4 Oct 2, 2024

This vulnerability allows authenticated low-privileged attackers to upload or delete files on Cisco NDFC devices via a specific REST API endpoint with missing authorization controls. Only systems runn...

CVE-2024-20491

MEDIUM CVSS 6.3 Oct 2, 2024

This vulnerability in Cisco Nexus Dashboard Insights allows attackers who obtain tech support files to view remote controller admin credentials in clear text. Organizations using affected Cisco Nexus ...

CVE-2024-20444

MEDIUM CVSS 5.5 Oct 2, 2024

This vulnerability allows authenticated remote attackers with network-admin privileges to execute arbitrary commands on Cisco Nexus Dashboard Fabric Controller (NDFC) systems. Attackers can overwrite ...

CVE-2024-20441

MEDIUM CVSS 5.7 Oct 2, 2024

This vulnerability allows authenticated low-privileged attackers to access sensitive configuration information through a specific REST API endpoint in Cisco NDFC. Attackers can download configuration ...