2024-07-14 02:06:08 +00:00

60 lines
2.7 KiB
JSON

{
"id": "CVE-2024-20302",
"sourceIdentifier": "ykramarz@cisco.com",
"published": "2024-04-03T17:15:48.323",
"lastModified": "2024-04-03T17:24:18.150",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability in the tenant security implementation of Cisco Nexus Dashboard Orchestrator (NDO) could allow an authenticated, remote attacker to modify or delete tenant templates on an affected system. \r\n \r\nThis vulnerability is due to improper access controls within tenant security. An attacker who is using a valid user account with write privileges and either a Site Manager or Tenant Manager role could exploit this vulnerability. A successful exploit could allow the attacker to modify or delete tenant templates under non-associated tenants, which could disrupt network traffic."
},
{
"lang": "es",
"value": "Una vulnerabilidad en la implementaci\u00f3n de seguridad de inquilinos de Cisco Nexus Dashboard Orchestrator (NDO) podr\u00eda permitir que un atacante remoto autenticado modifique o elimine plantillas de inquilinos en un SYSTEM afectado. Esta vulnerabilidad se debe a controles de acceso inadecuados dentro de la seguridad de los inquilinos. Un atacante que utilice una cuenta de usuario v\u00e1lida con privilegios de escritura y una funci\u00f3n de administrador del sitio o administrador de inquilinos podr\u00eda aprovechar esta vulnerabilidad. Un exploit exitoso podr\u00eda permitir al atacante modificar o eliminar plantillas de inquilinos en inquilinos no asociados, lo que podr\u00eda interrumpir el tr\u00e1fico de la red."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "ykramarz@cisco.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"availabilityImpact": "LOW",
"baseScore": 5.4,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 2.8,
"impactScore": 2.5
}
]
},
"weaknesses": [
{
"source": "ykramarz@cisco.com",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-284"
}
]
}
],
"references": [
{
"url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ndo-upav-YRqsCcSP",
"source": "ykramarz@cisco.com"
}
]
}