Improper Authorization in Cisco NDFC REST API
Summary
A REST API endpoint shared by Cisco Nexus Dashboard and Nexus Dashboard Fabric Controller fails to enforce its protection mechanism, allowing an authenticated, low-privileged, remote attacker to view sensitive information (such as HTTP proxy and NTP configuration) and modify certain image files.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N — 5.4 Medium.
Details
The endpoint relies on a protection mechanism that can be bypassed, so checks intended to gate access do not actually constrain a low privileged caller. The result is partial confidentiality and integrity impact.
Impact
Disclosure of configuration data and unauthorized modification of image files by an under-privileged user.
Remediation
- Upgrade to a fixed Cisco NDFC / Nexus Dashboard release per the Cisco advisory.