CVE-2024-20350 - CVE House
Back to Database
Status published High CVE-2024-20350

Cisco Catalyst Center Static SSH Host Key Vulnerability

Vulnerability Description

A vulnerability in the SSH server of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an unauthenticated, remote attacker to impersonate a Cisco Catalyst Center appliance. This vulnerability is due to the presence of a static SSH host key. An attacker could exploit this vulnerability by performing a machine-in-the-middle attack on SSH connections, which could allow the attacker to intercept traffic between SSH clients and a Cisco Catalyst Center appliance. A successful exploit could allow the attacker to impersonate the affected appliance, inject commands into the terminal session, and steal valid user credentials.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-20350

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Cisco Digital Network Architecture Center (DNA Center)
Vulnerable Versions:
1.4.0.0, 2.1.1.0, 2.1.1.3, 2.1.2.0, 2.1.2.3, 2.1.2.4, 2.1.2.5, 2.2.1.0, 2.1.2.6, 2.2.2.0, 2.2.2.1, 2.2.2.3, 2.1.2.7, 2.2.1.3, 2.2.3.0, 2.2.2.4, 2.2.2.5, 2.2.3.3, 2.2.2.7, 2.2.2.6, 2.2.2.8, 2.2.3.4, 2.1.2.8, 2.3.2.1, 2.3.2.1-AIRGAP, 2.3.2.1-AIRGAP-CA, 2.2.3.5, 2.3.3.0, 2.3.3.3, 2.3.3.1-AIRGAP, 2.3.3.1, 2.3.2.3, 2.3.3.3-AIRGAP, 2.2.3.6, 2.2.2.9, 2.3.3.0-AIRGAP, 2.3.3.3-AIRGAP-CA, 2.3.3.4, 2.3.3.4-AIRGAP, 2.3.3.4-AIRGAP-MDNAC, 2.3.3.4-HF1, 2.3.4.0, 2.3.3.5, 2.3.3.5-AIRGAP, 2.3.4.0-AIRGAP, 2.3.4.3, 2.3.4.3-AIRGAP, 2.3.3.6, 2.3.5.0, 2.3.3.6-AIRGAP, 2.3.5.0-AIRGAP, 2.3.3.6-AIRGAP-MDNAC, 2.3.5.0-AIRGAP-MDNAC, 2.3.3.7, 2.3.3.7-AIRGAP, 2.3.3.7-AIRGAP-MDNAC, 2.3.6.0, 2.3.3.6-70045-HF1, 2.3.3.7-72328-AIRGAP, 2.3.3.7-72323, 2.3.3.7-72328-MDNAC, 2.3.5.3, 2.3.5.3-AIRGAP-MDNAC, 2.3.5.3-AIRGAP, 2.3.6.0-AIRGAP, 2.3.7.0, 2.3.7.0-AIRGAP, 2.3.7.0-AIRGAP-MDNAC, 2.3.7.0-VA, 2.3.5.4, 2.3.5.4-AIRGAP, 2.3.5.4-AIRGAP-MDNAC, 2.3.7.3, 2.3.7.3-AIRGAP, 2.3.7.3-AIRGAP-MDNAC, 2.3.5.5-AIRGAP, 2.3.5.5, 2.3.5.5-AIRGAP-MDNAC, 2.3.7.4, 2.3.7.4-AIRGAP, 2.3.7.4-AIRGAP-MDNAC, 1.0.0.0, 2.3.5.5-70026-HF70, 2.3.5.5-70026-HF51, 2.3.5.5-70026-HF52, 2.3.5.5-70026-HF53

Timeline

Official Publish: September 25th, 2024
Last Modified: September 27th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses (CWE)