Cisco Nexus Dashboard Fabric Controller SSH Host Key Validation Vulnerability

🚨 SEVERITY: HIGH — CVSS 8.7 Security Advisory

TL;DR 📌

A high-severity vulnerability has been identified in the SSH implementation of Cisco Nexus Dashboard Fabric Controller (NDFC), allowing unauthenticated remote attackers to impersonate managed devices due to insufficient SSH host key validation. Cisco has released software updates to address this issue, with no workarounds available.

What happened 🕵️‍♂️

A vulnerability in the SSH implementation of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauthenticated, remote attacker to impersonate Cisco NDFC-managed devices. This vulnerability arises from insufficient SSH host key validation, enabling attackers to perform machine-in-the-middle attacks on SSH connections. A successful exploit could lead to traffic interception and user credential capture.

Affected products 🖥️

This vulnerability affects Cisco Nexus Dashboard Fabric Controller (NDFC) across all device configurations. Notably, Cisco NDFC releases 11.5 and earlier were previously known as Cisco Data Center Network Manager (DCNM). The following products are confirmed not vulnerable:

  • Nexus Dashboard Insights
  • Nexus Dashboard Orchestrator (NDO)

Fixed software 🔧

Upgrade to at least the first fixed release in your train (or later):

Product / Release Train First Fixed Release Notes
ISE / ISE-PIC 3.1 Migrate to a fixed release.
ISE / ISE-PIC 3.2 3.2(2f)
ISE / ISE-PIC 1.0 Initial public release.

Workarounds 🧯

There are no workarounds available to mitigate this vulnerability.

Risk in context 🎯

With a CVSS score of 8.7, this vulnerability is classified as high severity. The potential for an attacker to impersonate managed devices and capture sensitive user credentials poses a significant risk to network security.

Fast facts ⚡

  • Vulnerability: SSH Host Key Validation
  • CVSS Score: 8.7 (High)
  • Exploitation: Machine-in-the-middle attacks possible
  • No workarounds available
  • Fixed releases: 3.2(2f) and migration for 3.1

For leadership 🧭

Executive summary. Cisco Nexus Dashboard Fabric Controller does not properly verify SSH host keys when connecting to the devices it manages, which could let an attacker on the network path impersonate a managed switch and capture administrative credentials. There is no workaround, so upgrading NDFC should be scheduled as a priority change rather than left for routine patching.

Why it matters:

  • NDFC’s SSH connections to managed fabric devices are not authenticated against a trusted host key, so a machine-in-the-middle can pose as a legitimate switch or controller without needing valid credentials first.
  • A successful attack can expose the credentials NDFC uses to log into managed devices, which typically have broad configuration and control access across the data centre fabric.
  • The flaw affects all NDFC configurations, including deployments upgraded from the older Cisco Data Center Network Manager (DCNM) on 11.5 and earlier.
  • No workaround exists, so exposure remains until the affected controller is upgraded to a fixed release.

Now / Next / Later:

  • Now: Identify every Cisco NDFC instance in your estate, including those migrated from DCNM 11.5 or earlier, and confirm which software release each is running.
  • Next: Schedule an upgrade of affected NDFC controllers to the fixed release identified for your train during the next available change window, since no mitigating workaround exists.
  • Later: Add SSH host key verification checks and NDFC-to-managed-device trust configuration to routine fabric health and security audits so similar validation gaps are caught before they reach production.