Info-Disclosure
- Improper Authorization in Cisco NDFC REST API
A REST API endpoint in Cisco Nexus Dashboard and NDFC lets an authenticated, low-privileged attacker view sensitive information and modify certain files.
- Information Exposure in Cisco NDFC REST API
A REST API endpoint in Cisco Nexus Dashboard and NDFC discloses sensitive information to an authenticated, low-privileged attacker through its responses.
- Improper Authorization Information Disclosure in Cisco NDFC REST API
A specific REST API endpoint in Cisco NDFC enforces authorization improperly, letting an authenticated, low-privileged attacker read sensitive information.
- Sensitive Information Disclosure via Cisco NDFC Configuration Backups
Cisco NDFC stores secrets in cleartext within config-only and full backup files, so anyone with access to a backup can recover device credentials and private keys.
- Sensitive Information in Cisco NDFC Tech-Support Files
A logging function in Cisco NDFC and Nexus Dashboard Orchestrator records HTTP proxy credentials in cleartext within tech-support files.
- Unauthenticated Arbitrary File Read in Cisco NDFC (PnP)
The Out-of-Band Plug and Play feature of Cisco NDFC lets an unauthenticated, remote attacker read arbitrary files from the PnP container via improper path validation.