Summary

A REST API endpoint shared by Cisco Nexus Dashboard and Nexus Dashboard Fabric Controller fails to enforce its protection mechanism, allowing an authenticated, low-privileged, remote attacker to view sensitive information (such as HTTP proxy and NTP configuration) and modify certain image files.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N — 5.4 Medium.

Details

The endpoint relies on a protection mechanism that can be bypassed, so checks intended to gate access do not actually constrain a low privileged caller. The result is partial confidentiality and integrity impact.

Impact

Disclosure of configuration data and unauthorized modification of image files by an under-privileged user.

Remediation

  • Upgrade to a fixed Cisco NDFC / Nexus Dashboard release per the Cisco advisory.

References