Summary

Cisco Nexus Dashboard Fabric Controller stores sensitive information improperly inside config-only and full backup files. An attacker who obtains a backup file can read that information in the clear.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N — 8.6 High (scope-changed).

Details

Backups are expected to be portable artifacts, but NDFC writes secrets into them without adequate protection. Exposed material includes NDFC connected device credentials, the NDFC site-manager private key, and the scheduled backup encryption key.

Impact

Recovery of device credentials and key material from a backup file, enabling impersonation of NDFC and access to managed devices.

Remediation

  • Upgrade to a fixed Cisco NDFC release per the Cisco advisory.
  • Treat existing backup files as sensitive; rotate exposed credentials and keys.

References