VYPR
Medium severity6.0NVD Advisory· Published Apr 3, 2024· Updated Jun 17, 2026

CVE-2024-20282

CVE-2024-20282

Description

A vulnerability in Cisco Nexus Dashboard could allow an authenticated, local attacker with valid rescue-user credentials to elevate privileges to root on an affected device. This vulnerability is due to insufficient protections for a sensitive access token. An attacker could exploit this vulnerability by using this token to access resources within the device infrastructure. A successful exploit could allow an attacker to gain root access to the filesystem or hosted containers on an affected device.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:cisco:nexus_dashboard:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:cisco:nexus_dashboard:*:*:*:*:*:*:*:*range: <3.1(1k)
    • (no CPE)
    • (no CPE)range: 1.1(0c)

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.