Summary

A flaw in the REST API and web UI of Cisco Nexus Dashboard Fabric Controller allows an authenticated, low privileged, remote attacker to inject commands. Successful exploitation runs arbitrary commands on the CLI of an NDFC managed device with network-admin privileges.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H — 9.9 Critical.

Note: NVD/NIST scores this 8.8 High; Cisco PSIRT rates it 9.9 Critical.

Details

The vulnerability stems from improper user authorization combined with insufficient validation of command arguments. A low privileged user can reach functionality that builds and runs commands against managed devices, escalating to network admin command execution on those devices.

Impact

Arbitrary command execution on NDFC managed devices.

Remediation

  • Upgrade to a fixed Cisco NDFC release per the Cisco advisory.

References