cisco-sa-ndidv-LmXdvAf2: Cisco Nexus Dashboard Information Disclosure Vulnerability
A vulnerability in Cisco Nexus Dashboard could allow an authenticated, remote attacker to learn cluster deployment information on an affected device.This vulnerability is due to improper access controls on a specific API endpoint. An attacker could exploit this vulnerability by
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-ndidv-LmXdvAf2?
The severity of cisco-sa-ndidv-LmXdvAf2 is classified as high due to its potential for unauthorized information disclosure.
How do I fix cisco-sa-ndidv-LmXdvAf2?
To mitigate cisco-sa-ndidv-LmXdvAf2, ensure proper access controls are configured and apply the latest security patches from Cisco.
Who is affected by cisco-sa-ndidv-LmXdvAf2?
Cisco Nexus Dashboard implementations that do not have the necessary access controls in place are affected by cisco-sa-ndidv-LmXdvAf2.
What kind of information can an attacker access due to cisco-sa-ndidv-LmXdvAf2?
An attacker exploiting cisco-sa-ndidv-LmXdvAf2 could learn confidential cluster deployment information from the affected device.
Is authentication required to exploit cisco-sa-ndidv-LmXdvAf2?
Yes, an authenticated remote attacker can exploit cisco-sa-ndidv-LmXdvAf2 to gain access to the vulnerable API endpoint.