GPU VulnDB

Database/Control plane, storage & DevOps

Cisco Nexus Dashboard Fabric Controller (SQL injection): A read-only NDFC user executes arbitrary SQL on the controller

CVE-2024-20536Control plane, storage & DevOpscurated

Impact

A read-only NDFC user executes arbitrary SQL on the controller database - which holds the fabric's configuration and credentials.

Who can reach it

Authenticated read-only remote access to NDFC.

What to do

Upgrade NDFC per cisco-sa-ndfc-sqli-CyPPAxrL.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.