Missing Authorization File Upload/Delete in Cisco NDFC REST API
Summary
A specific REST API endpoint of Cisco Nexus Dashboard Fabric Controller does not enforce authorization, allowing an authenticated, low-privileged, remote attacker to upload or delete files within certain containers.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L — 5.4 Medium.
Details
The endpoint accepts file upload and delete operations without verifying the caller’s authorization, so a low-privileged user can alter files they should not control.
Impact
Unauthorized modification or removal of files in affected containers, potentially disrupting NDFC functionality.
Remediation
- Upgrade to a fixed Cisco NDFC release per the Cisco advisory.