Arbitrary Code Execution via SCP Path Traversal in Cisco NDFC
Summary
Cisco Nexus Dashboard Fabric Controller does not properly validate file paths during Secure Copy Protocol (SCP) transfers. An authenticated, low-privileged, remote attacker can use path traversal to write a file to an arbitrary location and have it execute with root privileges.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H — 8.8 High.
Details
The SCP upload path is not constrained to its intended directory, so traversal sequences let an attacker drop a malicious file where it will be executed. The resulting code runs as root, turning a low-privileged foothold into full host compromise.
Impact
Root-level remote code execution on the NDFC host.
Remediation
- Upgrade to a fixed Cisco NDFC release per the Cisco advisory.