CVE-2024-20302

A vulnerability in the tenant security implementation of Cisco Nexus Dashboard Orchestrator (NDO) could allow an authenticated, remote attacker to modify or delete tenant templates on an affected system. This vulnerability is due to improper access controls within tenant security. An attacker who is using a valid user account with write privileges and either a Site Manager or Tenant Manager role could exploit this vulnerability. A successful exploit could allow the attacker to modify or delete tenant templates under non-associated tenants, which could disrupt network traffic.
Configurations

No configuration.

History

21 Nov 2024, 08:52

Type Values Removed Values Added
References () https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ndo-upav-YRqsCcSP - () https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ndo-upav-YRqsCcSP -
Summary
  • (es) Una vulnerabilidad en la implementación de seguridad de inquilinos de Cisco Nexus Dashboard Orchestrator (NDO) podría permitir que un atacante remoto autenticado modifique o elimine plantillas de inquilinos en un SYSTEM afectado. Esta vulnerabilidad se debe a controles de acceso inadecuados dentro de la seguridad de los inquilinos. Un atacante que utilice una cuenta de usuario válida con privilegios de escritura y una función de administrador del sitio o administrador de inquilinos podría aprovechar esta vulnerabilidad. Un exploit exitoso podría permitir al atacante modificar o eliminar plantillas de inquilinos en inquilinos no asociados, lo que podría interrumpir el tráfico de la red.

03 Apr 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-03 17:15

Updated : 2024-11-21 08:52


NVD link : CVE-2024-20302

Mitre link : CVE-2024-20302

CVE.ORG link : CVE-2024-20302


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control