CVE-2024-20350

HIGH

Cisco Catalyst Center - Impersonation

Title source: llm
STIX 2.1

Description

A vulnerability in the SSH server of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an unauthenticated, remote attacker to impersonate a Cisco Catalyst Center appliance. This vulnerability is due to the presence of a static SSH host key. An attacker could exploit this vulnerability by performing a machine-in-the-middle attack on SSH connections, which could allow the attacker to intercept traffic between SSH clients and a Cisco Catalyst Center appliance. A successful exploit could allow the attacker to impersonate the affected appliance, inject commands into the terminal session, and steal valid user credentials.

Scores

CVSS v3 7.5
EPSS 0.0250
EPSS Percentile 85.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-321
Status published
Products (49)
cisco/catalyst_center 1.0.0
cisco/catalyst_center 1.4.0.0
cisco/catalyst_center 2.1.1.0
cisco/catalyst_center 2.1.1.3
cisco/catalyst_center 2.1.2.0
cisco/catalyst_center 2.1.2.3
cisco/catalyst_center 2.1.2.4
cisco/catalyst_center 2.1.2.5
cisco/catalyst_center 2.1.2.6
cisco/catalyst_center 2.1.2.7
... and 39 more
Published Sep 25, 2024
Tracked Since Feb 18, 2026