Unauthenticated Arbitrary File Read in Cisco NDFC (PnP)
Summary
The Out-of-Band (OOB) Plug and Play (PnP) feature of Cisco Nexus Dashboard Fabric Controller exposes a request handler that does not properly constrain file paths. An unauthenticated, remote attacker can read arbitrary files from the PnP container.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N — 7.5 High.
Details
Input that selects the file to return is not validated against the intended
directory, so path traversal sequences let the attacker escape it. No
authentication is required and impact is confidentiality-only (C:H/I:N/A:N).
Impact
Disclosure of sensitive files readable by the PnP container, which may include configuration or credential material useful for further attack.
Remediation
- Upgrade to a fixed Cisco NDFC release per the Cisco advisory.