Vulnerability in REST API of Cisco Nexus Dashboard and Nexus Dashboard Fabric Controller
CVE-2025-20348

5MEDIUM

Key Information:

Vendor

Cisco

Vendor
CVE Published:
27 August 2025

Badges

👾 Exploit Exists

What is CVE-2025-20348?

A security flaw has been identified in the REST API endpoints of Cisco Nexus Dashboard and Cisco Nexus Dashboard Fabric Controller. This flaw could be exploited by an authenticated, low-privileged attacker to gain unauthorized access to sensitive information, including configurations related to HTTP Proxy and NTP settings. The absence of proper authorization controls on specific REST API endpoints may allow an attacker to send specially crafted API commands, enabling them to perform limited administrative actions. By doing so, an attacker could potentially upload files, alter existing images, and compromise critical configurations, posing a significant risk to the integrity and security of affected devices.

Affected Version(s)

Cisco Nexus Dashboard 1.1(3e)

Cisco Nexus Dashboard 1.1(3c)

Cisco Nexus Dashboard 1.1(3d)

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20348 : Vulnerability in REST API of Cisco Nexus Dashboard and Nexus Dashboard Fabric Controller