CVE-2024-20350: Cisco Catalyst Center
High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.
A vulnerability in the SSH server of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an unauthenticated, remote attacker to impersonate a Cisco Catalyst Center appliance. This vulnerability is due to the presence of a static SSH host key. An attacker could exploit this vulnerability by performing a machine-in-the-middle attack on SSH connections, which could allow the attacker to intercept traffic between SSH clients and a Cisco Catalyst Center appliance. A successful exploit could allow the attacker to impersonate the affected appliance, inject commands into the terminal session, and steal valid user credentials.
Affected products
- Cisco Catalyst Center: version 1.0.0 only; version 1.4.0.0 only; version 2.1.1.0 only; version 2.1.1.3 only; version 2.1.2.0 only; version 2.1.2.3 only; …
Published 2024-09-25. Last modified 2026-06-17.