cisco-sa-ndfc-cmdinj-UvYZrKfr: Cisco Nexus Dashboard Fabric Controller Arbitrary Command Execution Vulnerability
A vulnerability in the REST API and web UI of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, low-privileged, remote attacker to perform a command injection attack against an affected device. This vulnerability is due to improper
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-ndfc-cmdinj-UvYZrKfr?
The severity of cisco-sa-ndfc-cmdinj-UvYZrKfr is classified as high due to its potential impact on the affected device.
How do I fix cisco-sa-ndfc-cmdinj-UvYZrKfr?
To mitigate the cisco-sa-ndfc-cmdinj-UvYZrKfr vulnerability, upgrade the Cisco Nexus Dashboard Fabric Controller to a patched version as specified in the security advisory.
What is the nature of the attack for cisco-sa-ndfc-cmdinj-UvYZrKfr?
The cisco-sa-ndfc-cmdinj-UvYZrKfr vulnerability allows an authenticated, low-privileged, remote attacker to execute a command injection attack.
Which software is affected by cisco-sa-ndfc-cmdinj-UvYZrKfr?
The vulnerability cisco-sa-ndfc-cmdinj-UvYZrKfr affects the Cisco Nexus Dashboard Fabric Controller.
Can the cisco-sa-ndfc-cmdinj-UvYZrKfr vulnerability be exploited remotely?
Yes, the cisco-sa-ndfc-cmdinj-UvYZrKfr vulnerability can be exploited by remote attackers who are authenticated with low privileges.