Improper Authorization Information Disclosure in Cisco NDFC REST API
Summary
A specific REST API endpoint of Cisco Nexus Dashboard Fabric Controller applies authorization incorrectly, allowing an authenticated, low privileged, remote attacker to learn sensitive information on an affected device.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N — 6.5 Medium.
Details
The endpoint returns sensitive data without confirming the caller is authorized to view it.
Impact
Disclosure of sensitive configuration or operational data to under-privileged users.
Remediation
- Upgrade to a fixed Cisco NDFC release per the Cisco advisory.