#VU114489 Protection Mechanism Failure in Nexus Dashboard and Cisco Nexus Dashboard Fabric Controller (NDFC) - CVE-2025-20348

 

#VU114489 Protection Mechanism Failure in Nexus Dashboard and Cisco Nexus Dashboard Fabric Controller (NDFC) - CVE-2025-20348

Published: August 28, 2025


Vulnerability identifier: #VU114489
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2025-20348
CWE-ID: CWE-693
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Nexus Dashboard
Cisco Nexus Dashboard Fabric Controller (NDFC)
Software vendor:
Cisco Systems, Inc

Description

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to missing authorization controls on some REST API endpoints. A remote user can send specially crafted API requests to gain access to sensitive information or upload and modify files on the target device.


Remediation

Install updates from vendor's website.

External links