Cisco Security Advisory
Follow
Cisco Nexus Dashboard and Nexus Dashboard Fabric Controller Unauthorized REST API Vulnerabilities
Multiple vulnerabilities have been identified in the REST API endpoints of Cisco Nexus Dashboard and Cisco Nexus Dashboard Fabric Controller. These flaws stem from missing authorization controls on certain REST API endpoints. An authenticated, low-privileged, remote attacker can exploit these vulnerabilities. The attacker would achieve this by sending specially crafted API requests to an affected endpoint. Successful exploitation could grant the attacker limited administrator functions. These functions include accessing sensitive information on HTTP Proxy and NTP configurations. Additionally, attackers could upload or modify image files on the affected devices. Importantly, these vulnerabilities do not impact the web-based management interface. Cisco has released software updates to address these security issues. No workarounds are available to mitigate these vulnerabilities.