Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2024-20491 Details

Description

A vulnerability in a logging function of Cisco Nexus Dashboard Insights could allow an attacker with access to a tech support file to view sensitive information. This vulnerability exists because remote controller credentials are recorded in an internal log that is stored in the tech support file. An attacker could exploit this vulnerability by accessing a tech support file that is generated from an affected system. A successful exploit could allow the attacker to view remote controller admin credentials in clear text. Note: Best practice is to store debug logs and tech support files safely and to share them only with trusted parties because they may contain sensitive information.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-532Insertion of Sensitive Information into Log File[email protected]
CWE-200Exposure of Sensitive Information to an Unauthorized Actor[email protected]

Affected Products

ProductVersions
cisco nexus dashboard fabric controller
>= 12.1.0, < 12.2.2.241

CPE

  • cpe:2.3:a:cisco:nexus_dashboard_fabric_controller:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
cisco nexus dashboard insights
< 6.4.0
>= 6.5.0, < 6.5.1.32

CPE

  • cpe:2.3:a:cisco:nexus_dashboard_insights:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
cisco nexus dashboard orchestrator
< 4.2\(3o\)
>= 4.4.0, < 4.4.1.1012

CPE

  • cpe:2.3:a:cisco:nexus_dashboard_orchestrator:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

4 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2024-20491
NVD Published Date:
Oct 2, 2024
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2024-20491 Details - Not Deferred