📦 Nexus Dashboard

by Cisco

🔍 What is Nexus Dashboard?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-20857

CRITICAL CVSS 9.8 Jul 21, 2022

CVE-2022-20857 is a critical vulnerability in Cisco Nexus Dashboard that allows unauthenticated remote attackers to execute arbitrary commands, read/upload container images, or perform CSRF attacks. T...

CVE-2022-20861

CRITICAL CVSS 9.8 Jul 21, 2022

CVE-2022-20861 allows unauthenticated remote attackers to execute arbitrary commands, read/upload container images, or perform CSRF attacks on Cisco Nexus Dashboard. Organizations using affected Cisco...

CVE-2021-44228

CRITICAL CVSS 10.0 Dec 10, 2021

CVE-2021-44228 (Log4Shell) is a critical remote code execution vulnerability in Apache Log4j2 that allows attackers to execute arbitrary code by exploiting JNDI lookups in log messages. This affects a...

CVE-2025-20163

HIGH CVSS 8.7 Jun 4, 2025

This vulnerability allows unauthenticated remote attackers to impersonate Cisco NDFC-managed devices via SSH man-in-the-middle attacks due to insufficient host key validation. Attackers could intercep...

CVE-2023-20014

HIGH CVSS 7.5 Mar 1, 2023

An unauthenticated remote attacker can cause denial of service on Cisco Nexus Dashboard by sending continuous DNS requests. This vulnerability affects the coredns service and can cause service disrupt...

CVE-2022-20860

HIGH CVSS 7.4 Jul 21, 2022

This vulnerability allows an unauthenticated remote attacker to perform man-in-the-middle attacks on SSL/TLS connections between Cisco Nexus Dashboard and its controllers, potentially altering communi...

CVE-2025-20348

MEDIUM CVSS 5.0 Aug 27, 2025

This vulnerability allows authenticated low-privileged attackers to bypass authorization controls on REST API endpoints in Cisco Nexus Dashboard and NDFC. Attackers can view sensitive configuration da...

CVE-2025-20344

MEDIUM CVSS 6.5 Aug 27, 2025

This vulnerability allows authenticated administrators to exploit path traversal via crafted backup files in Cisco Nexus Dashboard, potentially gaining root shell access. It affects Cisco Nexus Dashbo...

CVE-2025-20347

MEDIUM CVSS 5.4 Aug 27, 2025

This vulnerability allows authenticated low-privileged attackers to bypass authorization controls on REST API endpoints in Cisco Nexus Dashboard and NDFC. Attackers can view sensitive configuration da...

CVE-2025-20150

MEDIUM CVSS 5.3 Apr 16, 2025

An unauthenticated remote attacker can enumerate valid LDAP usernames on vulnerable Cisco Nexus Dashboard systems by sending authentication requests. This affects organizations using Cisco Nexus Dashb...

CVE-2024-20477

MEDIUM CVSS 5.4 Oct 2, 2024

This vulnerability allows authenticated low-privileged attackers to upload or delete files on Cisco NDFC devices via a specific REST API endpoint with missing authorization controls. Only systems runn...

CVE-2024-20441

MEDIUM CVSS 5.7 Oct 2, 2024

This vulnerability allows authenticated low-privileged attackers to access sensitive configuration information through a specific REST API endpoint in Cisco NDFC. Attackers can download configuration ...