cisco-sa-ndfc-shkv-snQJtjrp: Cisco Nexus Dashboard Fabric Controller SSH Host Key Validation Vulnerability
A vulnerability in the SSH implementation of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauthenticated, remote attacker to impersonate Cisco NDFC-managed devices.This vulnerability is due to insufficient SSH host key validation. An attacker could exploit this vulnerability by performing a machine-in-the-middle attack on SSH connections to Cisco NDFC-managed devices, which could allow an attacker to intercept this traffic. A successful exploit could allow the attacker to impersonate a managed device and capture user credentials.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ndfc-shkv-snQJtjrp
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-ndfc-shkv-snQJtjrp?
The cisco-sa-ndfc-shkv-snQJtjrp vulnerability has a high severity rating due to its potential for unauthorized remote access.
How do I fix cisco-sa-ndfc-shkv-snQJtjrp?
To fix cisco-sa-ndfc-shkv-snQJtjrp, update the Cisco Nexus Dashboard Fabric Controller to the latest version that addresses this vulnerability.
Who is affected by cisco-sa-ndfc-shkv-snQJtjrp?
The cisco-sa-ndfc-shkv-snQJtjrp vulnerability affects users of the Cisco Nexus Dashboard Fabric Controller who utilize the SSH feature.
What can an attacker do with cisco-sa-ndfc-shkv-snQJtjrp?
An attacker exploiting cisco-sa-ndfc-shkv-snQJtjrp could impersonate Cisco NDFC-managed devices and potentially launch further attacks.
Is there a workaround for cisco-sa-ndfc-shkv-snQJtjrp?
Currently, there is no official workaround available for the cisco-sa-ndfc-shkv-snQJtjrp vulnerability; updating software is the recommended course of action.