Use of Hard-coded Cryptographic Key in Cisco Intelligent Node (iNode) and Cisco Intelligent Node (iNode) Manager - CVE-2024-20323
Published: July 18, 2024
Vulnerability identifier: #VU94513
CSH Severity: Medium
CVSS v4: 8.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-20323
CWE-ID: CWE-321
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to use of hard-coded cryptographic key. A remote attacker can perform a man-in-the-middle (MitM) attack to read data that is meant for a legitimate device and modify the startup configuration of an associated node.
Affected software
Cisco Intelligent Node (iNode)
Cisco Intelligent Node (iNode) Manager
Cisco Intelligent Node (iNode) Manager
How to mitigate CVE-2024-20323
Install updates from vendor's website.
Cisco Intelligent Node (iNode) - update to 4.0.0
Cisco Intelligent Node (iNode) Manager - update to 24.1
Cisco Intelligent Node (iNode) Manager - update to 24.1