REST API Vulnerability in Cisco Nexus Dashboard and Fabric Controller
CVE-2025-20347
5.4MEDIUM
What is CVE-2025-20347?
A vulnerability exists in Cisco Nexus Dashboard and Nexus Dashboard Fabric Controller due to inadequate authorization controls on certain REST API endpoints. This flaw allows an authenticated, low-privileged remote attacker to potentially view sensitive configurations, such as HTTP Proxy and NTP settings, as well as upload and alter files on affected devices. Exploitation involves sending specifically crafted API requests, which may enable limited administrative functions, creating risks related to data integrity and exposure.
Affected Version(s)
Cisco Data Center Network Manager 11.2(1)
Cisco Data Center Network Manager 7.0(2)
Cisco Data Center Network Manager 10.3(2)IPFM