VendorsCisconexus_dashboardall versions
Vulnerabilities

Cisco Nexus

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

26CVEs
CVE-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
Published 2021-12-10 · Analyzed
10.0KEV3 PoCEPSS 1.000
CVE-2022-20857
Cisco Nexus Dashboard Unauthorized Access Vulnerabilities
Published 2022-07-21 · Modified
9.8EPSS 0.016
CVE-2022-20858
Cisco Nexus Dashboard Unauthorized Access Vulnerabilities
Published 2022-07-21 · Modified
9.8EPSS 0.013
CVE-2022-20861
Cisco Nexus Dashboard Unauthorized Access Vulnerabilities
Published 2022-07-21 · Modified
9.8EPSS 0.006
CVE-2024-20281
A vulnerability in the web-based management interface of Cisco Nexus Dashboard and Cisco Nexus Dashboard hosted services could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the web-based management interface on an affected system. An attacker could exploit this vulnerability by persuading a user to click a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user. If the affected user has administrative privileges, these actions could include modifying the system configuration and creating new privileged accounts. Note: There are internal security mechanisms in place that limit the scope of this exploit, reducing the Security Impact Rating of this vulnerability.
Published 2024-04-03 · Analyzed
8.8EPSS 0.003
CVE-2025-20163
Cisco Nexus Dashboard Fabric Controller SSH Host Key Vulnerability
Published 2025-06-04 · Analyzed
8.7EPSS 0.004
CVE-2023-20014
A vulnerability in the DNS functionality of Cisco Nexus Dashboard Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to the improper processing of DNS requests. An attacker could exploit this vulnerability by sending a continuous stream of DNS requests to an affected device. A successful exploit could allow the attacker to cause the coredns service to stop working or cause the device to reload, resulting in a DoS condition.
Published 2023-02-16 · Modified
7.5EPSS 0.010
CVE-2022-20860
Cisco Nexus Dashboard SSL Certificate Validation Vulnerability
Published 2022-07-21 · Modified
7.4EPSS 0.005
CVE-2025-20344
Cisco Nexus Dashboard Path Traversal Vulnerability
Published 2025-08-27 · Analyzed
7.2EPSS 0.006
CVE-2022-20908
Cisco Nexus Dashboard Privilege Escalation Vulnerabilities
Published 2022-07-21 · Modified
6.7EPSS 0.002
CVE-2022-20909
Cisco Nexus Dashboard Privilege Escalation Vulnerabilities
Published 2022-07-21 · Modified
6.7EPSS 0.002
CVE-2022-20907
Cisco Nexus Dashboard Privilege Escalation Vulnerabilities
Published 2022-07-21 · Modified
6.7EPSS 0.002
CVE-2022-20906
Cisco Nexus Dashboard Privilege Escalation Vulnerabilities
Published 2022-07-21 · Modified
6.7EPSS 0.002
CVE-2022-20913
Cisco Nexus Dashboard Arbitrary File Write Vulnerability
Published 2022-07-21 · Modified
6.5EPSS 0.011
CVE-2024-20441
Cisco Nexus Dashboard Fabric Controller Unauthorized API Endpoint Vulnerability
Published 2024-10-02 · Analyzed
6.5EPSS 0.005
CVE-2026-20042
Cisco Nexus Dashboard Configuration REST API Unauthorized Access Vulnerability
Published 2026-04-01 · Analyzed
6.5EPSS 0.003
CVE-2024-20438
Cisco Nexus Dashboard Fabric Controller Unauthorized REST API Vulnerability
Published 2024-10-02 · Analyzed
6.3EPSS 0.004
CVE-2023-20053
A vulnerability in the web-based management interface of Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. This vulnerability is due to insufficient user input validation. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
Published 2023-02-16 · Modified
6.1EPSS 0.005
CVE-2024-20282
A vulnerability in Cisco Nexus Dashboard could allow an authenticated, local attacker with valid rescue-user credentials to elevate privileges to root on an affected device. This vulnerability is due to insufficient protections for a sensitive access token. An attacker could exploit this vulnerability by using this token to access resources within the device infrastructure. A successful exploit could allow an attacker to gain root access to the filesystem or hosted containers on an affected device.
Published 2024-04-03 · Analyzed
6.0EPSS 0.002
CVE-2024-20477
Cisco Nexus Dashboard Fabric Controller Unauthorized REST API Endpoint Vulnerability
Published 2024-10-02 · Analyzed
5.4EPSS 0.005
CVE-2024-20442
Cisco Nexus Dashboard Unauthorized API Endpoints Vulnerability
Published 2024-10-02 · Analyzed
5.4EPSS 0.004
CVE-2025-20347
Cisco Nexus Dashboard Fabric Controller Unauthorized REST API Vulnerability
Published 2025-08-27 · Analyzed
5.4EPSS 0.003
CVE-2025-20150
Cisco Nexus Dashboard Username Enumeration Vulnerability
Published 2025-04-16 · Analyzed
5.3EPSS 0.005
CVE-2025-20348
Cisco Nexus Dashboard Unauthorized REST API Vulnerability
Published 2025-08-27 · Analyzed
5.0EPSS 0.003
CVE-2026-20174
Cisco Nexus Dashboard Insights Arbitrary File Write Vulnerability
Published 2026-04-01 · Analyzed
4.9EPSS 0.005
CVE-2024-20283
A vulnerability in Cisco Nexus Dashboard could allow an authenticated, remote attacker to learn cluster deployment information on an affected device. This vulnerability is due to improper access controls on a specific API endpoint. An attacker could exploit this vulnerability by sending queries to the API endpoint. A successful exploit could allow an attacker to access metrics and information about devices in the Nexus Dashboard cluster.
Published 2024-04-03 · Analyzed
4.3EPSS 0.004