REST API Vulnerability in Cisco Nexus Dashboard and Fabric Controller
CVE-2025-20347

5.4MEDIUM

Key Information:

Vendor

Cisco

Vendor
CVE Published:
27 August 2025

Badges

👾 Exploit Exists

What is CVE-2025-20347?

A vulnerability exists in Cisco Nexus Dashboard and Nexus Dashboard Fabric Controller due to inadequate authorization controls on certain REST API endpoints. This flaw allows an authenticated, low-privileged remote attacker to potentially view sensitive configurations, such as HTTP Proxy and NTP settings, as well as upload and alter files on affected devices. Exploitation involves sending specifically crafted API requests, which may enable limited administrative functions, creating risks related to data integrity and exposure.

Affected Version(s)

Cisco Data Center Network Manager 11.2(1)

Cisco Data Center Network Manager 7.0(2)

Cisco Data Center Network Manager 10.3(2)IPFM

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20347 : REST API Vulnerability in Cisco Nexus Dashboard and Fabric Controller