Cisco Nexus Dashboard and NDFC Unauthorized REST API Vulnerability Allowing Information Disclosure and File Modification

Vulnerability

A vulnerability exists in the REST API endpoints of Cisco Nexus Dashboard and Cisco Nexus Dashboard Fabric Controller (NDFC) due to inadequate authorization controls. This flaw enables authenticated, low-privileged, remote attackers to access sensitive information or upload and alter files on affected devices. Exploitation of this vulnerability could allow attackers to perform limited administrative tasks, such as retrieving confidential HTTP Proxy and NTP configuration details, uploading images, and corrupting image files on the device.

Impact

Successful exploitation could permit an attacker to execute limited administrative functions, including accessing sensitive HTTP Proxy and NTP configuration information, uploading images, and damaging image files on the affected device.

Remediation

Cisco has released software updates to address these vulnerabilities. For Cisco Nexus Dashboard releases 3.2 and earlier, users should migrate to a fixed release. For Cisco Nexus Dashboard release 4.1, users should upgrade to version 4.1(1g). For Cisco NDFC, migrate to an appropriate fixed Cisco Nexus Dashboard release.

Added: Aug 27, 2025, 5:23 PM
Updated: Aug 27, 2025, 5:23 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
5.0
exploitability
4.9
remediation
7.7
relevance
0.4
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.