8.1
CVE-2024-20350
- EPSS 0.45%
- Veröffentlicht 25.09.2024 17:15:15
- Zuletzt bearbeitet 30.07.2025 16:08:54
- Quelle psirt@cisco.com
- Teams Watchlist Login
- Unerledigt Login
A vulnerability in the SSH server of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an unauthenticated, remote attacker to impersonate a Cisco Catalyst Center appliance. This vulnerability is due to the presence of a static SSH host key. An attacker could exploit this vulnerability by performing a machine-in-the-middle attack on SSH connections, which could allow the attacker to intercept traffic between SSH clients and a Cisco Catalyst Center appliance. A successful exploit could allow the attacker to impersonate the affected appliance, inject commands into the terminal session, and steal valid user credentials.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Catalyst Center Version1.0.0
Cisco ≫ Catalyst Center Version1.4.0.0
Cisco ≫ Catalyst Center Version2.1.1.0
Cisco ≫ Catalyst Center Version2.1.1.3
Cisco ≫ Catalyst Center Version2.1.2.0
Cisco ≫ Catalyst Center Version2.1.2.3
Cisco ≫ Catalyst Center Version2.1.2.4
Cisco ≫ Catalyst Center Version2.1.2.5
Cisco ≫ Catalyst Center Version2.1.2.6
Cisco ≫ Catalyst Center Version2.1.2.7
Cisco ≫ Catalyst Center Version2.1.2.8
Cisco ≫ Catalyst Center Version2.2.1.0
Cisco ≫ Catalyst Center Version2.2.1.3
Cisco ≫ Catalyst Center Version2.2.2.0
Cisco ≫ Catalyst Center Version2.2.2.1
Cisco ≫ Catalyst Center Version2.2.2.3
Cisco ≫ Catalyst Center Version2.2.2.4
Cisco ≫ Catalyst Center Version2.2.2.5
Cisco ≫ Catalyst Center Version2.2.2.6
Cisco ≫ Catalyst Center Version2.2.2.7
Cisco ≫ Catalyst Center Version2.2.2.8
Cisco ≫ Catalyst Center Version2.2.2.9
Cisco ≫ Catalyst Center Version2.2.3.0
Cisco ≫ Catalyst Center Version2.2.3.3
Cisco ≫ Catalyst Center Version2.2.3.4
Cisco ≫ Catalyst Center Version2.2.3.5
Cisco ≫ Catalyst Center Version2.2.3.6
Cisco ≫ Catalyst Center Version2.3.2.1
Cisco ≫ Catalyst Center Version2.3.2.1-airgap
Cisco ≫ Catalyst Center Version2.3.2.1-airgap-ca
Cisco ≫ Catalyst Center Version2.3.2.3
Cisco ≫ Catalyst Center Version2.3.3.0
Cisco ≫ Catalyst Center Version2.3.3.0-airgap
Cisco ≫ Catalyst Center Version2.3.3.1
Cisco ≫ Catalyst Center Version2.3.3.1-airgap
Cisco ≫ Catalyst Center Version2.3.3.3
Cisco ≫ Catalyst Center Version2.3.3.3-airgap
Cisco ≫ Catalyst Center Version2.3.3.3-airgap-ca
Cisco ≫ Catalyst Center Version2.3.3.4 Update-
Cisco ≫ Catalyst Center Version2.3.3.4 Updatehotfix1
Cisco ≫ Catalyst Center Version2.3.3.4-airgap
Cisco ≫ Catalyst Center Version2.3.3.4-airgap-mdnac
Cisco ≫ Catalyst Center Version2.3.3.5
Cisco ≫ Catalyst Center Version2.3.3.5-airgap
Cisco ≫ Catalyst Center Version2.3.3.6
Cisco ≫ Catalyst Center Version2.3.3.6-70045 Updatehotfix1
Cisco ≫ Catalyst Center Version2.3.3.6-airgap
Cisco ≫ Catalyst Center Version2.3.3.6-airgap-mdnac
Cisco ≫ Catalyst Center Version2.3.3.7
Cisco ≫ Catalyst Center Version2.3.3.7-72323
Cisco ≫ Catalyst Center Version2.3.3.7-72328-airgap
Cisco ≫ Catalyst Center Version2.3.3.7-72328-mdnac
Cisco ≫ Catalyst Center Version2.3.3.7-airgap
Cisco ≫ Catalyst Center Version2.3.3.7-airgap-mdnac
Cisco ≫ Catalyst Center Version2.3.4.0
Cisco ≫ Catalyst Center Version2.3.4.0-airgap
Cisco ≫ Catalyst Center Version2.3.4.3
Cisco ≫ Catalyst Center Version2.3.4.3-airgap
Cisco ≫ Catalyst Center Version2.3.5.0
Cisco ≫ Catalyst Center Version2.3.5.0-airgap
Cisco ≫ Catalyst Center Version2.3.5.0-airgap-mdnac
Cisco ≫ Catalyst Center Version2.3.5.3
Cisco ≫ Catalyst Center Version2.3.5.3-airgap
Cisco ≫ Catalyst Center Version2.3.5.3-airgap-mdnac
Cisco ≫ Catalyst Center Version2.3.5.4
Cisco ≫ Catalyst Center Version2.3.5.4-airgap
Cisco ≫ Catalyst Center Version2.3.5.4-airgap-mdnac
Cisco ≫ Catalyst Center Version2.3.5.5
Cisco ≫ Catalyst Center Version2.3.5.5-70026 Updatehotfix51
Cisco ≫ Catalyst Center Version2.3.5.5-70026 Updatehotfix52
Cisco ≫ Catalyst Center Version2.3.5.5-70026 Updatehotfix53
Cisco ≫ Catalyst Center Version2.3.5.5-70026 Updatehotfix70
Cisco ≫ Catalyst Center Version2.3.5.5-airgap
Cisco ≫ Catalyst Center Version2.3.5.5-airgap-mdnac
Cisco ≫ Catalyst Center Version2.3.6.0
Cisco ≫ Catalyst Center Version2.3.6.0-airgap
Cisco ≫ Catalyst Center Version2.3.7.0
Cisco ≫ Catalyst Center Version2.3.7.0-airgap
Cisco ≫ Catalyst Center Version2.3.7.0-airgap-mdnac
Cisco ≫ Catalyst Center Version2.3.7.0-va
Cisco ≫ Catalyst Center Version2.3.7.3
Cisco ≫ Catalyst Center Version2.3.7.3-airgap
Cisco ≫ Catalyst Center Version2.3.7.3-airgap-mdnac
Cisco ≫ Catalyst Center Version2.3.7.4
Cisco ≫ Catalyst Center Version2.3.7.4-airgap
Cisco ≫ Catalyst Center Version2.3.7.4-airgap-mdnac
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.45% | 0.626 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 8.1 | 2.2 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
|
psirt@cisco.com | 7.5 | 1.6 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-321 Use of Hard-coded Cryptographic Key
The use of a hard-coded cryptographic key significantly increases the possibility that encrypted data may be recovered.