REST API Vulnerability in Cisco Nexus Dashboard and Fabric Controller
CVE-2025-20347
What is CVE-2025-20347?
A vulnerability exists in Cisco Nexus Dashboard and Nexus Dashboard Fabric Controller due to inadequate authorization controls on certain REST API endpoints. This flaw allows an authenticated, low-privileged remote attacker to potentially view sensitive configurations, such as HTTP Proxy and NTP settings, as well as upload and alter files on affected devices. Exploitation involves sending specifically crafted API requests, which may enable limited administrative functions, creating risks related to data integrity and exposure.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cisco Data Center Network Manager 11.2(1)
Cisco Data Center Network Manager 7.0(2)
Cisco Data Center Network Manager 10.3(2)IPFM
References
CVSS V3.1
Timeline
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved