CVE Feed

    Dashboard / CVE / CVE-2024-20282

    CVE-2024-20282

    A vulnerability in Cisco Nexus Dashboard could allow an authenticated, local attacker with valid rescue-user credentials to elevate privileges to root on an affected device. This vulnerability is due to insufficient protections for a sensitive access token. An attacker could exploit this vulnerability by using this token to access resources within the device infrastructure. A successful exploit could allow an attacker to gain root access to the filesystem or hosted containers on an affected device.

    Published:Apr 3, 2024
    Last Modified:May 7, 2025
    EPS:Apr 3, 2024
    EPSS Score:0.00052
    CVSS Score:6

    Affected Products

    Vendor
    Cisco
    Product
    Nexus Dashboard

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High