CVE-2024-20302

A vulnerability in the tenant security implementation of Cisco Nexus Dashboard Orchestrator (NDO) could allow an authenticated, remote attacker to modify or delete tenant templates on an affected syst

Severity
Medium 5.4
CVSS 3.1
Remote, needs privileges or user interaction what this means
Exploited
Not listed
EPSS
0.004
30.0th percentile
Discovered by
Vendor
Vendor-published field
Published
Apr 3, 2024
Assigned by cisco

Description

A vulnerability in the tenant security implementation of Cisco Nexus Dashboard Orchestrator (NDO) could allow an authenticated, remote attacker to modify or delete tenant templates on an affected system. This vulnerability is due to improper access controls within tenant security. An attacker who is using a valid user account with write privileges and either a Site Manager or Tenant Manager role could exploit this vulnerability. A successful exploit could allow the attacker to modify or delete tenant templates under non-associated tenants, which could disrupt network traffic.

Weakness: CWE-284

Affected products

Vendor Product Category Matched by
Cisco Cisco Nexus Dashboard Network & Security Management cna-assigner
Vendor-reported products (1)
  • Cisco · Cisco Nexus Dashboard Orchestrator

Vendor advisory

cisco-sa-ndo-upav-YRqsCcSP

Cisco Nexus Dashboard Orchestrator Unauthorized Policy Actions Vulnerability

Cisco’s rating: Medium (advisory CVSS 5.4) · Published Apr 3, 2024

Bug ID: CSCwi31692

The vendor’s rating applies to the whole advisory and can differ from this CVE’s own CVSS severity. Where this comes from

Something wrong here?