Missing Authorization File Read/Write in Cisco NDFC REST API
Summary
A REST API endpoint of Cisco Nexus Dashboard Fabric Controller does not enforce authorization, allowing an authenticated, low-privileged, remote attacker to read or write files on an affected device.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N — 5.4 Medium.
Details
The endpoint performs file operations without verifying that the caller is authorized for them, so a low privileged user can reach functionality intended for higher roles. Impact is limited to partial confidentiality and integrity.
Impact
Unauthorized read and write of files within the application’s reach, which can expose or tamper with data a low-privileged user should not touch.
Remediation
- Upgrade to a fixed Cisco NDFC release per the Cisco advisory.