GPU VulnDB

Database/Control plane, storage & DevOps

Cisco Nexus Dashboard Fabric Controller (SSH host key validation): NDFC does not validate the SSH host keys

CVE-2025-20163Control plane, storage & DevOpscurated

Impact

NDFC does not validate the SSH host keys of the switches it manages, so anyone positioned on the management network can impersonate a managed switch and machine-in-the-middle the controller's sessions with it — harvesting the device credentials NDFC presents and feeding back forged state. Affects all NDFC versions regardless of configuration, which means every NDFC deployment ever built has been trusting its management network implicitly.

Who can reach it

Unauthenticated attacker with a position on the path between NDFC and its managed devices — a compromised management-network host, a rogue device, or ARP/route manipulation on the OOB VLAN.

What to do

Upgrade NDFC to a release that pins host keys. Controller software upgrade. Also rotate every switch credential NDFC holds, since they may have been captured — that credential rotation across a fabric is the expensive part, not the upgrade.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.