Insertion of Sensitive Information Into Sent Data in Nexus Dashboard and Cisco Nexus Dashboard Fabric Controller (NDFC) - CVE-2025-20347

 

Insertion of Sensitive Information Into Sent Data in Nexus Dashboard and Cisco Nexus Dashboard Fabric Controller (NDFC) - CVE-2025-20347

Published: August 28, 2025


Vulnerability identifier: #VU114488
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-20347
CWE-ID: CWE-201
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to missing authorization controls on some REST API endpoints. A remote user can send specially crafted API requests to gain access to sensitive information or upload and modify files on the target device.


Affected software

Nexus Dashboard
Cisco Nexus Dashboard Fabric Controller (NDFC)

How to mitigate CVE-2025-20347

Install updates from vendor's website.

Nexus Dashboard - update to 4.1(1g)

External References

Related Security Bulletins