Information Exposure in Cisco NDFC REST API
Summary
A REST API endpoint shared by Cisco Nexus Dashboard and Nexus Dashboard Fabric Controller returns sensitive information in its responses to an authenticated, low-privileged, remote attacker.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N — 5.0 Medium (scope-changed).
Details
The endpoint includes sensitive data in data it sends back to the caller without verifying the caller should receive it.
Impact
Disclosure of sensitive information to under-privileged users.
Remediation
- Upgrade to a fixed Cisco NDFC / Nexus Dashboard release per the Cisco advisory.