Cisco Nexus Dashboard and Nexus Dashboard Fabric Controller Unauthorized REST API Vulnerabilities

🚨 SEVERITY: MEDIUM — CVSS 5.4 Security Advisory

TL;DR 📌

Cisco Nexus Dashboard and Nexus Dashboard Fabric Controller have vulnerabilities in their REST API that could allow low-privileged authenticated attackers to access sensitive information or modify files. The highest CVSS score is 5.4 (Medium severity). No workarounds are available, and updates are necessary to mitigate the risks.

What happened 🕵️‍♂️

Multiple vulnerabilities have been identified in the REST API endpoints of Cisco Nexus Dashboard and Cisco Nexus Dashboard Fabric Controller (NDFC). These vulnerabilities arise from missing authorization controls, enabling low-privileged authenticated attackers to potentially view sensitive information or perform limited administrative functions, such as uploading images or accessing configuration details. Exploitation requires sending crafted API requests to affected endpoints.

Affected products 🖥️

  • Cisco Nexus Dashboard
  • Cisco Nexus Dashboard Fabric Controller (NDFC)

Fixed software 🔧

Upgrade to the first fixed release in your train (or later):

Release / Product First Fixed Release Notes
3.2 and earlier Migrate to a fixed release.
4.1 4.1(1g)
1.0 Initial public release.
Cisco Nexus Dashboard 4.1(1g) 3.2 and earlier

Workarounds 🧯

There are no workarounds that address these vulnerabilities.

Risk in context 🎯

The vulnerabilities are rated as Medium severity (CVSS 5.4). They require authenticated access, which limits the potential attack surface but still poses a risk if low-privileged accounts are compromised. The lack of workarounds means that remediation through software updates is essential.

Fast facts ⚡

  • Vulnerabilities: CVE-2025-20347, CVE-2025-20348
  • Highest CVSS score: 5.4 (Medium)
  • Exploitation requires authenticated access
  • No known public exploitation at this time

For leadership 🧭

Executive summary. Two flaws in the REST API of Cisco Nexus Dashboard and Nexus Dashboard Fabric Controller let an already-logged-in, low-privileged user read sensitive information or carry out limited administrative actions such as uploading images or pulling configuration details. Severity is medium and there’s no workaround, so this should be scheduled into the next patch cycle rather than treated as an emergency.

Why it matters:

  • The flaw sits in the REST API endpoints of Nexus Dashboard and NDFC, the platforms used to manage and orchestrate Cisco data centre fabrics.
  • A low-privileged authenticated account, not an anonymous attacker, is enough to view sensitive configuration data or perform limited admin functions like uploading images.
  • There is no workaround, so exposure persists on any unpatched 3.2-or-earlier or pre-4.1(1g) deployment until the software is upgraded.
  • Because this touches fabric management infrastructure, unauthorized access to configuration details could expose network topology or credentials useful for further access.

Now / Next / Later:

  • Now: Identify every Nexus Dashboard and NDFC instance in your environment and check its version against the fixed releases (4.1(1g) or later, or migrate off 3.2 and earlier).
  • Next: Schedule the upgrade to 4.1(1g) or the applicable fixed release for each affected system in your next maintenance window, since no interim workaround exists.
  • Later: Review who holds low-privileged accounts on Nexus Dashboard/NDFC and tighten account provisioning and API access controls, given that this class of flaw relies on authenticated but under-privileged access.