CVE-2024-20444: Cisco Nexus Dashboard Fabric Controller

Medium severity, CVSS 5.5. EPSS: 0.8% chance of exploitation in the next 30 days.

A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC), formerly Cisco Data Center Network Manager (DCNM), could allow an authenticated, remote attacker with network-admin privileges to perform a command injection attack against an affected device.   This vulnerability is due to insufficient validation of command arguments. An attacker could exploit this vulnerability by submitting crafted command arguments to a specific REST API endpoint. A successful exploit could allow the attacker to overwrite sensitive files or crash a specific container, which would restart on its own, causing a low-impact denial of service (DoS) condition.

Affected products

  • Cisco Nexus Dashboard Fabric Controller: before 12.2.2 (fixed in 12.2.2)

Published 2024-10-02. Last modified 2026-06-17.