Database/Control plane, storage & DevOps
Cisco Nexus Dashboard Fabric Controller (SQL injection): A read-only NDFC user executes arbitrary SQL on the controller
CVE-2024-20536Control plane, storage & DevOpscurated
Impact
A read-only NDFC user executes arbitrary SQL on the controller database - which holds the fabric's configuration and credentials.
Who can reach it
Authenticated read-only remote access to NDFC.
What to do
Upgrade NDFC per cisco-sa-ndfc-sqli-CyPPAxrL.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.