8.1

CVE-2024-20350

A vulnerability in the SSH server of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an unauthenticated, remote attacker to impersonate a Cisco Catalyst Center appliance.

This vulnerability is due to the presence of a static SSH host key. An attacker could exploit this vulnerability by performing a machine-in-the-middle attack on SSH connections, which could allow the attacker to intercept traffic between SSH clients and a Cisco Catalyst Center appliance. A successful exploit could allow the attacker to impersonate the affected appliance, inject commands into the terminal session, and steal valid user credentials.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Data is provided by the National Vulnerability Database (NVD)
CiscoCatalyst Center Version1.0.0
CiscoCatalyst Center Version1.4.0.0
CiscoCatalyst Center Version2.1.1.0
CiscoCatalyst Center Version2.1.1.3
CiscoCatalyst Center Version2.1.2.0
CiscoCatalyst Center Version2.1.2.3
CiscoCatalyst Center Version2.1.2.4
CiscoCatalyst Center Version2.1.2.5
CiscoCatalyst Center Version2.1.2.6
CiscoCatalyst Center Version2.1.2.7
CiscoCatalyst Center Version2.1.2.8
CiscoCatalyst Center Version2.2.1.0
CiscoCatalyst Center Version2.2.1.3
CiscoCatalyst Center Version2.2.2.0
CiscoCatalyst Center Version2.2.2.1
CiscoCatalyst Center Version2.2.2.3
CiscoCatalyst Center Version2.2.2.4
CiscoCatalyst Center Version2.2.2.5
CiscoCatalyst Center Version2.2.2.6
CiscoCatalyst Center Version2.2.2.7
CiscoCatalyst Center Version2.2.2.8
CiscoCatalyst Center Version2.2.2.9
CiscoCatalyst Center Version2.2.3.0
CiscoCatalyst Center Version2.2.3.3
CiscoCatalyst Center Version2.2.3.4
CiscoCatalyst Center Version2.2.3.5
CiscoCatalyst Center Version2.2.3.6
CiscoCatalyst Center Version2.3.2.1
CiscoCatalyst Center Version2.3.2.1-airgap
CiscoCatalyst Center Version2.3.2.1-airgap-ca
CiscoCatalyst Center Version2.3.2.3
CiscoCatalyst Center Version2.3.3.0
CiscoCatalyst Center Version2.3.3.0-airgap
CiscoCatalyst Center Version2.3.3.1
CiscoCatalyst Center Version2.3.3.1-airgap
CiscoCatalyst Center Version2.3.3.3
CiscoCatalyst Center Version2.3.3.3-airgap
CiscoCatalyst Center Version2.3.3.3-airgap-ca
CiscoCatalyst Center Version2.3.3.4 Update-
CiscoCatalyst Center Version2.3.3.4 Updatehotfix1
CiscoCatalyst Center Version2.3.3.4-airgap
CiscoCatalyst Center Version2.3.3.4-airgap-mdnac
CiscoCatalyst Center Version2.3.3.5
CiscoCatalyst Center Version2.3.3.5-airgap
CiscoCatalyst Center Version2.3.3.6
CiscoCatalyst Center Version2.3.3.6-70045 Updatehotfix1
CiscoCatalyst Center Version2.3.3.6-airgap
CiscoCatalyst Center Version2.3.3.6-airgap-mdnac
CiscoCatalyst Center Version2.3.3.7
CiscoCatalyst Center Version2.3.3.7-72323
CiscoCatalyst Center Version2.3.3.7-72328-airgap
CiscoCatalyst Center Version2.3.3.7-72328-mdnac
CiscoCatalyst Center Version2.3.3.7-airgap
CiscoCatalyst Center Version2.3.3.7-airgap-mdnac
CiscoCatalyst Center Version2.3.4.0
CiscoCatalyst Center Version2.3.4.0-airgap
CiscoCatalyst Center Version2.3.4.3
CiscoCatalyst Center Version2.3.4.3-airgap
CiscoCatalyst Center Version2.3.5.0
CiscoCatalyst Center Version2.3.5.0-airgap
CiscoCatalyst Center Version2.3.5.0-airgap-mdnac
CiscoCatalyst Center Version2.3.5.3
CiscoCatalyst Center Version2.3.5.3-airgap
CiscoCatalyst Center Version2.3.5.3-airgap-mdnac
CiscoCatalyst Center Version2.3.5.4
CiscoCatalyst Center Version2.3.5.4-airgap
CiscoCatalyst Center Version2.3.5.4-airgap-mdnac
CiscoCatalyst Center Version2.3.5.5
CiscoCatalyst Center Version2.3.5.5-70026 Updatehotfix51
CiscoCatalyst Center Version2.3.5.5-70026 Updatehotfix52
CiscoCatalyst Center Version2.3.5.5-70026 Updatehotfix53
CiscoCatalyst Center Version2.3.5.5-70026 Updatehotfix70
CiscoCatalyst Center Version2.3.5.5-airgap
CiscoCatalyst Center Version2.3.5.5-airgap-mdnac
CiscoCatalyst Center Version2.3.6.0
CiscoCatalyst Center Version2.3.6.0-airgap
CiscoCatalyst Center Version2.3.7.0
CiscoCatalyst Center Version2.3.7.0-airgap
CiscoCatalyst Center Version2.3.7.0-airgap-mdnac
CiscoCatalyst Center Version2.3.7.0-va
CiscoCatalyst Center Version2.3.7.3
CiscoCatalyst Center Version2.3.7.3-airgap
CiscoCatalyst Center Version2.3.7.3-airgap-mdnac
CiscoCatalyst Center Version2.3.7.4
CiscoCatalyst Center Version2.3.7.4-airgap
CiscoCatalyst Center Version2.3.7.4-airgap-mdnac
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.45% 0.626
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.1 2.2 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
psirt@cisco.com 7.5 1.6 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-321 Use of Hard-coded Cryptographic Key

The use of a hard-coded cryptographic key significantly increases the possibility that encrypted data may be recovered.