Summary

A specific REST API endpoint of Cisco Nexus Dashboard Fabric Controller does not enforce authorization, allowing an authenticated, low-privileged, remote attacker to upload or delete files within certain containers.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L — 5.4 Medium.

Details

The endpoint accepts file upload and delete operations without verifying the caller’s authorization, so a low-privileged user can alter files they should not control.

Impact

Unauthorized modification or removal of files in affected containers, potentially disrupting NDFC functionality.

Remediation

  • Upgrade to a fixed Cisco NDFC release per the Cisco advisory.

References