CVE-2024-20350 describes a high-severity vulnerability in the SSH server of Cisco Catalyst Center, formerly Cisco DNA Center, stemming from a static SSH host key. This flaw allows an unauthenticated, remote attacker to perform a machine-in-the-middle attack, impersonating the appliance and intercepting SSH traffic. A successful exploit could lead to command injection and the theft of user credentials, with a CVSS score of 8.1 (HIGH). Currently, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed in CISA's KEV catalog, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.0CPE matchmatch criteria | cpe:2.3:a:cisco:catalyst_center:1.0.0:*:*:*:*:*:*:* | ||
1.4.0.0CPE matchmatch criteria | cpe:2.3:a:cisco:catalyst_center:1.4.0.0:*:*:*:*:*:*:* | ||
2.1.1.0CPE matchmatch criteria | cpe:2.3:a:cisco:catalyst_center:2.1.1.0:*:*:*:*:*:*:* | ||
2.1.1.3CPE matchmatch criteria | cpe:2.3:a:cisco:catalyst_center:2.1.1.3:*:*:*:*:*:*:* | ||
2.1.2.0CPE matchmatch criteria | cpe:2.3:a:cisco:catalyst_center:2.1.2.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.