#VU65657 Command Injection in Nexus Dashboard - CVE-2022-20857
Published: July 21, 2022
Nexus Dashboard
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to execute arbitrary commands on the target system.
The vulnerability exists due to insufficient access controls for a specific API. A remote attacker can send a specially crafted HTTP request and execute arbitrary commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.