Thursday, August 11, 2022
LetsAskBinu.com
  • Home
  • Cybersecurity
  • Cyber Threats
  • Hacking
  • Protection
  • Networking
  • Malware
  • Fintech
  • Internet Of Things
No Result
View All Result
LetsAskBinu.com
No Result
View All Result
Home Hacking

Cisco Nexus Dashboard Flaw Let Remote Attacker Execute Code

Researcher by Researcher
July 22, 2022
in Hacking
0
Cisco Nexus Dashboard Flaw Let Remote Attacker Execute Code
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter


Cisco Nexus Dashboard Flaw Let Remote Attacker Execute Arbitrary Commands

The Cisco Nexus Dashboard data center management solution was found to have severe vulnerabilities that Cisco has addressed recently. The total number of vulnerabilities identified was 45, which affected a wide variety of products and services.

A remote attacker can exploit these vulnerabilities to execute commands or perform actions with root privileges or Administrator permissions under the control of a system remotely.

Among the 45 vulnerabilities, the cybersecurity experts have marked them with three tags and here below we have mentioned:-

  • One flaw is rated as “Critical” in severity
  • Three flaws are rated as “High” in severity
  • Rest 41 flaws are rated as “Medium” in severity

Flaws affecting Cisco Nexus Dashboard


EHA

In terms of severity, the three most severe vulnerabilities are as follows:- 

Data centers and cloud network infrastructures are affected by these flaws in Cisco Nexus Dashboard. This could enable an unauthenticated remote attacker to perform the following illicit activities:-

  • Execute arbitrary commands
  • Read or upload container image files
  • Perform a cross-site request forgery attack

Flaw Profile

  • CVE ID: CVE-2022-20857
  • Summary: Cisco Nexus Dashboard Arbitrary Command Execution Vulnerability
  • Cisco Bug ID: CSCwa93560
  • Advisory ID: cisco-sa-ndb-mhcvuln-vpsBPJ9y
  • Security Impact Rating (SIR): Critical
  • CVSS Base Score: 9.8
  • Workarounds: Workarounds are not available.
  • CVE ID: CVE-2022-20861
  • Summary: Cisco Nexus Dashboard Cross-Site Request Forgery Vulnerability
  • Cisco Bug ID: CSCwa75451
  • Advisory ID: cisco-sa-ndb-mhcvuln-vpsBPJ9y
  • Security Impact Rating (SIR): High
  • CVSS Base Score: 8.8
  • Workarounds: Workarounds are not available.
  • CVE ID: CVE-2022-20858
  • Summary: Cisco Nexus Dashboard Container Image Read and Write Vulnerability
  • Cisco Bug ID: CSCwb24518
  • Advisory ID: cisco-sa-ndb-mhcvuln-vpsBPJ9y
  • Security Impact Rating (SIR): High
  • CVSS Base Score: 8.2
  • Workarounds: Workarounds are not available.

The Cisco Nexus Dashboard 1.1 version and subsequent versions are affected by the three vulnerabilities that were discovered during the ongoing internal security testing of Cisco Nexus Dashboards. Dashboard version 2.2(1e) has been released with fixes and improvements for the issues that have been reported.

No exploitation has been reported

It would be possible for the malicious images to be executed whenever a device or pod was rebooted or restarted. During internal security testing conducted by Cisco’s ASIG, security researchers found these vulnerabilities and reported them.

In response to a question from the PSIRT of Cisco, the company has confirmed that it is not aware of any exploits in the wild that are publicly available. 

It is possible that the attacker may also be able to view sensitive information if the exploit is successful, such as the administrator credentials for the affected controllers.

As a side note, Cisco also released patches for 10 security flaws a little over two weeks after releasing the initial updates.

You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity and hacking news updates.





Source link

Related articles

Hackers Use Open Redirect Vulnerabilities to Deliver Phishing Content

Hackers Use Open Redirect Vulnerabilities to Deliver Phishing Content

August 10, 2022
Hackers Exploiting High-Severity Zimbra Flaw to Steal Email Account Credentials

Hackers Exploiting High-Severity Zimbra Flaw to Steal Email Account Credentials

August 8, 2022
Tags: attackerCiscocodeDashboardExecuteFlawNexusRemote
Share76Tweet47

Related Posts

Hackers Use Open Redirect Vulnerabilities to Deliver Phishing Content

Hackers Use Open Redirect Vulnerabilities to Deliver Phishing Content

August 10, 2022
0

Researchers at Resecurity noticed threat actors leveraging Open Redirect Vulnerabilities which is popular in online services and apps to evade...

Hackers Exploiting High-Severity Zimbra Flaw to Steal Email Account Credentials

Hackers Exploiting High-Severity Zimbra Flaw to Steal Email Account Credentials

August 8, 2022
0

Zimbra CVE-2022-27824 has been added to the CISA’s “Known Exploited Vulnerabilities” catalog as a new vulnerability. Hackers are actively exploiting...

24-Year-Old Australian Hacker Arrested For Creating and Selling Spyware

24-Year-Old Australian Hacker Arrested For Creating and Selling Spyware

August 2, 2022
0

A 24-year-old man was arrested and charged with creating and selling spyware, triggering a global law enforcement operation. As a...

Critical SonicWall Flaw Allows SQL injection

Critical SonicWall Flaw Allows SQL injection

July 25, 2022
0

A critical SQL injection (SQLi) vulnerability was recently patched by the network security company SonicWall as a result of a...

Entrust Hacked – Attackers Stole Data From Internal Systems

Entrust Hacked – Attackers Stole Data From Internal Systems

July 25, 2022
0

Entrust, a big name in digital security, announced recently on its website that it has been attacked by hackers. During...

Load More
  • Trending
  • Comments
  • Latest
Brave browser’s Tor mode exposed users’ dark web activity

Brave browser’s Tor mode exposed users’ dark web activity

February 18, 2022
This Week in Fintech: TFT Bi-Weekly News Roundup 08/02

This Week in Fintech: TFT Bi-Weekly News Roundup 15/03

March 15, 2022
QNAP Escalation Vulnerability Let Attackers Gain Administrator Privileges

QNAP Escalation Vulnerability Let Attackers Gain Administrator Privileges

March 15, 2022
A first look at threat intelligence and threat hunting tools

A first look at threat intelligence and threat hunting tools

March 15, 2022
Beware! Facebook accounts being hijacked via Messenger prize phishing chats

Beware! Facebook accounts being hijacked via Messenger prize phishing chats

0
Shoulder surfing: Watch out for eagle‑eyed snoopers peeking at your phone

Shoulder surfing: Watch out for eagle‑eyed snoopers peeking at your phone

0
Remote work causing security issues for system and IT administrators

Remote work causing security issues for system and IT administrators

0
Elementor WordPress plugin has a gaping security hole – update now – Naked Security

Elementor WordPress plugin has a gaping security hole – update now – Naked Security

0
U.S. Gov Offers $5M Reward For North Korean Cybercrime Intel

How Three Ransomware Groups Targeted One Vulnerable Network

August 11, 2022
High-Severity Flaw in Argo CD is Information Leak Risk

Organizations Warned of Critical Vulnerabilities in NetModule Routers

August 11, 2022
Join the SD-WAN webinar: How to Extend Network Visibility and Optimize the SaaS Experience

Join the SD-WAN webinar: How to Extend Network Visibility and Optimize the SaaS Experience

August 11, 2022
Makulu Linux Shift makes shifting between desktop layouts easy

Makulu Linux Shift makes shifting between desktop layouts easy

August 10, 2022

Recent Posts

U.S. Gov Offers $5M Reward For North Korean Cybercrime Intel

How Three Ransomware Groups Targeted One Vulnerable Network

August 11, 2022
High-Severity Flaw in Argo CD is Information Leak Risk

Organizations Warned of Critical Vulnerabilities in NetModule Routers

August 11, 2022
Join the SD-WAN webinar: How to Extend Network Visibility and Optimize the SaaS Experience

Join the SD-WAN webinar: How to Extend Network Visibility and Optimize the SaaS Experience

August 11, 2022

Categories

  • Cyber Threats
  • Cybersecurity
  • Fintech
  • Hacking
  • Internet Of Things
  • Malware
  • Networking
  • Protection

Tags

Access Android attack Attacks banking BiWeekly bug Cisco critical Cyber Cybersecurity Data devices Digital exploited financial Finds Fintech Flaw flaws Google Group Hackers Krebs Latest malware Microsoft million Network News open Payments phishing Ransomware RoundUp security Software TFT Threat Top vulnerability warns Week Windows zeroday

© 2022 Lets Ask Binu All Rights Reserved

No Result
View All Result
  • Home
  • Cybersecurity
  • Cyber Threats
  • Hacking
  • Protection
  • Networking
  • Malware
  • Fintech
  • Internet Of Things

© 2022 Lets Ask Binu All Rights Reserved