Argument Injection in Cisco NDFC (Network-Admin)
Summary
Cisco Nexus Dashboard Fabric Controller (formerly Cisco DCNM) does not sufficiently validate command arguments. An authenticated, remote attacker with network-admin privileges can inject crafted arguments into an underlying command.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:L — 5.5 Medium.
Details
User supplied values are passed to a command without proper argument neutralization, so an attacker can append or alter argument delimiters.
Impact
File corruption or container crashes within NDFC, affecting integrity and availability of the controller.
Remediation
- Upgrade to a fixed Cisco NDFC release per the Cisco advisory.