QID 317210
Date Published: 2022-07-21
QID 317210: Cisco Nexus Dashboard Secure Sockets Layer (SSL) Certificate Validation Vulnerability (cisco-sa-nd-tlsvld-TbAQLp3N)
A vulnerability in the SSL/TLS implementation of Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to alter communications with associated controllers or view sensitive information.
Affected Products:
Cisco Nexus Dashboard (Cisco APIC)
Cisco APIC Version 1.1
Cisco APIC Version 2.0
Cisco APIC Version 2.1
Cisco APIC Version 2.2 Prior to 2.2(1h)
QID Detection Logic (Authenticated):
The check matches Cisco APIC version retrieved via Unix Auth using "show version" command.
Successful exploit could allow an unauthenticated, remote attacker to alter communications with associated controllers or view sensitive information.
Solution
Customers are advised to refer to cisco-sa-nd-tlsvld-TbAQLp3N for more information.
Vendor References
- cisco-sa-nd-tlsvld-TbAQLp3N -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nd-tlsvld-TbAQLp3N
CVEs related to QID 317210
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-nd-tlsvld-TbAQLp3N |
|