cve/2024/CVE-2024-20350.md
2025-09-29 21:09:30 +02:00

142 lines
13 KiB
Markdown

### [CVE-2024-20350](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20350)
![](https://img.shields.io/static/v1?label=Product&message=Cisco%20Digital%20Network%20Architecture%20Center%20(DNA%20Center)&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=1.0.0.0%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=1.4.0.0%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.1.1.0%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.1.1.3%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.1.2.0%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.1.2.3%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.1.2.4%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.1.2.5%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.1.2.6%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.1.2.7%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.1.2.8%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.2.1.0%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.2.1.3%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.2.2.0%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.2.2.1%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.2.2.3%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.2.2.4%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.2.2.5%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.2.2.6%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.2.2.7%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.2.2.8%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.2.2.9%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.2.3.0%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.2.3.3%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.2.3.4%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.2.3.5%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.2.3.6%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.2.1%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.2.1-AIRGAP%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.2.1-AIRGAP-CA%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.2.1-airgap%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.2.1-airgap-ca%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.2.3%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.3.0%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.3.0-AIRGAP%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.3.0-airgap%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.3.1%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.3.1-AIRGAP%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.3.1-airgap%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.3.3%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.3.3-AIRGAP%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.3.3-AIRGAP-CA%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.3.3-airgap%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.3.3-airgap-ca%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.3.4%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.3.4-AIRGAP%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.3.4-AIRGAP-MDNAC%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.3.4-HF1%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.3.4-airgap%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.3.4-airgap-mdnac%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.3.4-hf1%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.3.5%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.3.5-AIRGAP%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.3.5-airgap%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.3.6%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.3.6-70045-HF1%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.3.6-70045-hf1%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.3.6-AIRGAP%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.3.6-AIRGAP-MDNAC%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.3.6-airgap%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.3.6-airgap-mdnac%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.3.7%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.3.7-72323%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.3.7-72328-AIRGAP%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.3.7-72328-MDNAC%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.3.7-72328-airgap%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.3.7-72328-mdnac%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.3.7-AIRGAP%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.3.7-AIRGAP-MDNAC%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.3.7-airgap%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.3.7-airgap-mdnac%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.4.0%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.4.0-AIRGAP%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.4.0-airgap%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.4.3%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.4.3-AIRGAP%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.4.3-airgap%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.5.0%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.5.0-AIRGAP%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.5.0-AIRGAP-MDNAC%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.5.0-airgap%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.5.0-airgap-mdnac%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.5.3%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.5.3-AIRGAP%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.5.3-AIRGAP-MDNAC%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.5.3-airgap%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.5.3-airgap-mdnac%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.5.4%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.5.4-AIRGAP%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.5.4-AIRGAP-MDNAC%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.5.4-airgap%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.5.4-airgap-mdnac%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.5.5%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.5.5-70026-HF51%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.5.5-70026-HF52%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.5.5-70026-HF53%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.5.5-70026-HF70%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.5.5-70026-hf51%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.5.5-70026-hf52%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.5.5-70026-hf53%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.5.5-70026-hf70%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.5.5-AIRGAP%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.5.5-AIRGAP-MDNAC%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.5.5-airgap%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.5.5-airgap-mdnac%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.6.0%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.6.0-AIRGAP%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.6.0-airgap%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.7.0%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.7.0-AIRGAP%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.7.0-AIRGAP-MDNAC%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.7.0-VA%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.7.0-airgap%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.7.0-airgap-mdnac%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.7.0-va%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.7.3%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.7.3-AIRGAP%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.7.3-AIRGAP-MDNAC%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.7.3-airgap%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.7.3-airgap-mdnac%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.7.4%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.7.4-AIRGAP%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.7.4-AIRGAP-MDNAC%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.7.4-airgap%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2.3.7.4-airgap-mdnac%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=Use%20of%20Hard-coded%20Cryptographic%20Key&color=brightgreen)
### Description
A vulnerability in the SSH server of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an unauthenticated, remote attacker to impersonate a Cisco Catalyst Center appliance.
This vulnerability is due to the presence of a static SSH host key. An attacker could exploit this vulnerability by performing a machine-in-the-middle attack on SSH connections, which could allow the attacker to intercept traffic between SSH clients and a Cisco Catalyst Center appliance. A successful exploit could allow the attacker to impersonate the affected appliance, inject commands into the terminal session, and steal valid user credentials.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/fkie-cad/nvd-json-data-feeds