8.1
CVE-2024-20350
- EPSS 0.45%
- Published 25.09.2024 17:15:15
- Last modified 30.07.2025 16:08:54
- Source psirt@cisco.com
- Teams watchlist Login
- Open Login
A vulnerability in the SSH server of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an unauthenticated, remote attacker to impersonate a Cisco Catalyst Center appliance. This vulnerability is due to the presence of a static SSH host key. An attacker could exploit this vulnerability by performing a machine-in-the-middle attack on SSH connections, which could allow the attacker to intercept traffic between SSH clients and a Cisco Catalyst Center appliance. A successful exploit could allow the attacker to impersonate the affected appliance, inject commands into the terminal session, and steal valid user credentials.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users. Login
Data is provided by the National Vulnerability Database (NVD)
Cisco ≫ Catalyst Center Version1.0.0
Cisco ≫ Catalyst Center Version1.4.0.0
Cisco ≫ Catalyst Center Version2.1.1.0
Cisco ≫ Catalyst Center Version2.1.1.3
Cisco ≫ Catalyst Center Version2.1.2.0
Cisco ≫ Catalyst Center Version2.1.2.3
Cisco ≫ Catalyst Center Version2.1.2.4
Cisco ≫ Catalyst Center Version2.1.2.5
Cisco ≫ Catalyst Center Version2.1.2.6
Cisco ≫ Catalyst Center Version2.1.2.7
Cisco ≫ Catalyst Center Version2.1.2.8
Cisco ≫ Catalyst Center Version2.2.1.0
Cisco ≫ Catalyst Center Version2.2.1.3
Cisco ≫ Catalyst Center Version2.2.2.0
Cisco ≫ Catalyst Center Version2.2.2.1
Cisco ≫ Catalyst Center Version2.2.2.3
Cisco ≫ Catalyst Center Version2.2.2.4
Cisco ≫ Catalyst Center Version2.2.2.5
Cisco ≫ Catalyst Center Version2.2.2.6
Cisco ≫ Catalyst Center Version2.2.2.7
Cisco ≫ Catalyst Center Version2.2.2.8
Cisco ≫ Catalyst Center Version2.2.2.9
Cisco ≫ Catalyst Center Version2.2.3.0
Cisco ≫ Catalyst Center Version2.2.3.3
Cisco ≫ Catalyst Center Version2.2.3.4
Cisco ≫ Catalyst Center Version2.2.3.5
Cisco ≫ Catalyst Center Version2.2.3.6
Cisco ≫ Catalyst Center Version2.3.2.1
Cisco ≫ Catalyst Center Version2.3.2.1-airgap
Cisco ≫ Catalyst Center Version2.3.2.1-airgap-ca
Cisco ≫ Catalyst Center Version2.3.2.3
Cisco ≫ Catalyst Center Version2.3.3.0
Cisco ≫ Catalyst Center Version2.3.3.0-airgap
Cisco ≫ Catalyst Center Version2.3.3.1
Cisco ≫ Catalyst Center Version2.3.3.1-airgap
Cisco ≫ Catalyst Center Version2.3.3.3
Cisco ≫ Catalyst Center Version2.3.3.3-airgap
Cisco ≫ Catalyst Center Version2.3.3.3-airgap-ca
Cisco ≫ Catalyst Center Version2.3.3.4 Update-
Cisco ≫ Catalyst Center Version2.3.3.4 Updatehotfix1
Cisco ≫ Catalyst Center Version2.3.3.4-airgap
Cisco ≫ Catalyst Center Version2.3.3.4-airgap-mdnac
Cisco ≫ Catalyst Center Version2.3.3.5
Cisco ≫ Catalyst Center Version2.3.3.5-airgap
Cisco ≫ Catalyst Center Version2.3.3.6
Cisco ≫ Catalyst Center Version2.3.3.6-70045 Updatehotfix1
Cisco ≫ Catalyst Center Version2.3.3.6-airgap
Cisco ≫ Catalyst Center Version2.3.3.6-airgap-mdnac
Cisco ≫ Catalyst Center Version2.3.3.7
Cisco ≫ Catalyst Center Version2.3.3.7-72323
Cisco ≫ Catalyst Center Version2.3.3.7-72328-airgap
Cisco ≫ Catalyst Center Version2.3.3.7-72328-mdnac
Cisco ≫ Catalyst Center Version2.3.3.7-airgap
Cisco ≫ Catalyst Center Version2.3.3.7-airgap-mdnac
Cisco ≫ Catalyst Center Version2.3.4.0
Cisco ≫ Catalyst Center Version2.3.4.0-airgap
Cisco ≫ Catalyst Center Version2.3.4.3
Cisco ≫ Catalyst Center Version2.3.4.3-airgap
Cisco ≫ Catalyst Center Version2.3.5.0
Cisco ≫ Catalyst Center Version2.3.5.0-airgap
Cisco ≫ Catalyst Center Version2.3.5.0-airgap-mdnac
Cisco ≫ Catalyst Center Version2.3.5.3
Cisco ≫ Catalyst Center Version2.3.5.3-airgap
Cisco ≫ Catalyst Center Version2.3.5.3-airgap-mdnac
Cisco ≫ Catalyst Center Version2.3.5.4
Cisco ≫ Catalyst Center Version2.3.5.4-airgap
Cisco ≫ Catalyst Center Version2.3.5.4-airgap-mdnac
Cisco ≫ Catalyst Center Version2.3.5.5
Cisco ≫ Catalyst Center Version2.3.5.5-70026 Updatehotfix51
Cisco ≫ Catalyst Center Version2.3.5.5-70026 Updatehotfix52
Cisco ≫ Catalyst Center Version2.3.5.5-70026 Updatehotfix53
Cisco ≫ Catalyst Center Version2.3.5.5-70026 Updatehotfix70
Cisco ≫ Catalyst Center Version2.3.5.5-airgap
Cisco ≫ Catalyst Center Version2.3.5.5-airgap-mdnac
Cisco ≫ Catalyst Center Version2.3.6.0
Cisco ≫ Catalyst Center Version2.3.6.0-airgap
Cisco ≫ Catalyst Center Version2.3.7.0
Cisco ≫ Catalyst Center Version2.3.7.0-airgap
Cisco ≫ Catalyst Center Version2.3.7.0-airgap-mdnac
Cisco ≫ Catalyst Center Version2.3.7.0-va
Cisco ≫ Catalyst Center Version2.3.7.3
Cisco ≫ Catalyst Center Version2.3.7.3-airgap
Cisco ≫ Catalyst Center Version2.3.7.3-airgap-mdnac
Cisco ≫ Catalyst Center Version2.3.7.4
Cisco ≫ Catalyst Center Version2.3.7.4-airgap
Cisco ≫ Catalyst Center Version2.3.7.4-airgap-mdnac
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.45% | 0.626 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 8.1 | 2.2 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
|
psirt@cisco.com | 7.5 | 1.6 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-321 Use of Hard-coded Cryptographic Key
The use of a hard-coded cryptographic key significantly increases the possibility that encrypted data may be recovered.