VYPR
Unrated severityNVD Advisory· Published Sep 25, 2024· Updated Sep 27, 2024

Cisco Catalyst Center Static SSH Host Key Vulnerability

CVE-2024-20350

Description

A vulnerability in the SSH server of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an unauthenticated, remote attacker to impersonate a Cisco Catalyst Center appliance.

This vulnerability is due to the presence of a static SSH host key. An attacker could exploit this vulnerability by performing a machine-in-the-middle attack on SSH connections, which could allow the attacker to intercept traffic between SSH clients and a Cisco Catalyst Center appliance. A successful exploit could allow the attacker to impersonate the affected appliance, inject commands into the terminal session, and steal valid user credentials.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cisco Catalyst Center contains a static SSH host key, enabling unauthenticated, remote attackers to perform machine-in-the-middle attacks, intercept traffic, and steal credentials.

Vulnerability

A vulnerability in the SSH server of Cisco Catalyst Center (formerly Cisco DNA Center) allows an unauthenticated, remote attacker to impersonate the appliance. This issue is due to the presence of a static SSH host key. Affected versions include all versions prior to the fixed release; exact version numbers are not specified in the advisory [1]. The vulnerability is reachable over the network without authentication.

Exploitation

An attacker can exploit this vulnerability by performing a machine-in-the-middle (MITM) attack on SSH connections to a Cisco Catalyst Center appliance. The attacker must be positioned to intercept network traffic between SSH clients and the appliance. By exploiting the static host key, the attacker can impersonate the affected appliance and inject commands into the terminal session, as well as steal valid user credentials [1].

Impact

Successful exploitation allows the attacker to impersonate the Cisco Catalyst Center appliance, intercept SSH traffic, inject arbitrary commands into the terminal session, and steal user credentials. This compromises the confidentiality and integrity of communications and could lead to further unauthorized access to the network [1].

Mitigation

Cisco has released free software updates that address this vulnerability. Customers with service contracts should obtain fixes through their usual update channels. Customers without service contracts should contact the Cisco Technical Assistance Center (TAC) to obtain fixed software. No workaround is mentioned in the advisory [1]. The advisory does not list this vulnerability as part of the Known Exploited Vulnerabilities (KEV) catalog.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.