Vulnerability in REST API of Cisco Nexus Dashboard and Nexus Dashboard Fabric Controller
CVE-2025-20348
What is CVE-2025-20348?
A security flaw has been identified in the REST API endpoints of Cisco Nexus Dashboard and Cisco Nexus Dashboard Fabric Controller. This flaw could be exploited by an authenticated, low-privileged attacker to gain unauthorized access to sensitive information, including configurations related to HTTP Proxy and NTP settings. The absence of proper authorization controls on specific REST API endpoints may allow an attacker to send specially crafted API commands, enabling them to perform limited administrative actions. By doing so, an attacker could potentially upload files, alter existing images, and compromise critical configurations, posing a significant risk to the integrity and security of affected devices.
Affected Version(s)
Cisco Nexus Dashboard 1.1(3e)
Cisco Nexus Dashboard 1.1(3c)
Cisco Nexus Dashboard 1.1(3d)