Summary

A REST API endpoint of Cisco Nexus Dashboard Fabric Controller does not enforce authorization, allowing an authenticated, low-privileged, remote attacker to read or write files on an affected device.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N — 5.4 Medium.

Details

The endpoint performs file operations without verifying that the caller is authorized for them, so a low privileged user can reach functionality intended for higher roles. Impact is limited to partial confidentiality and integrity.

Impact

Unauthorized read and write of files within the application’s reach, which can expose or tamper with data a low-privileged user should not touch.

Remediation

  • Upgrade to a fixed Cisco NDFC release per the Cisco advisory.

References