SSH Host Key Validation Bypass in Cisco NDFC
Summary
The SSH implementation in Cisco Nexus Dashboard Fabric Controller does not adequately validate the host keys of devices it connects to. An unauthenticated, remote attacker in a man-in-the-middle position can impersonate an NDFC managed device.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N — 8.7 High (scope-changed).
Details
When NDFC opens SSH connections to managed devices, it fails to verify that the presented host key matches the expected device. An attacker who can intercept that traffic can present their own key and have NDFC trust it, intercepting or altering the session.
Impact
Machine-in-the-middle interception and manipulation of NDFC-to-device traffic, including potential capture of credentials and configuration data.
Remediation
- Upgrade to a fixed Cisco NDFC release per the Cisco advisory.