Cisco Nexus Dashboard Path Traversal Vulnerability

🚨 SEVERITY: MEDIUM — CVSS 6.5 Security Advisory

TL;DR 📌

A medium-severity path traversal vulnerability has been identified in Cisco Nexus Dashboard, allowing authenticated remote attackers to gain root privileges. No workarounds are available, and users are advised to upgrade to fixed software releases.

What happened 🕵️‍♂️

A vulnerability in the backup restore functionality of Cisco Nexus Dashboard could allow an authenticated, remote attacker to conduct a path traversal attack. This issue arises from insufficient validation of backup file contents. An attacker with valid Administrator credentials could exploit this vulnerability by restoring a crafted backup file, potentially gaining root privileges on the affected device.

Affected products 🖥️

The vulnerability affects Cisco Nexus Dashboard, regardless of device configuration. The following products are confirmed not to be vulnerable:

  • Nexus Dashboard Fabric Controller (NDFC)
  • Nexus Dashboard Insights
  • Nexus Dashboard Orchestrator (NDO)

Fixed software 🔧

Upgrade to the first fixed release in your train (or later):

Release / Product First Fixed Release Notes
3.2 and earlier Migrate to a fixed release.
4.1 4.1(1g)
1.0 Initial public release.
Cisco Nexus Dashboard 4.1(1g) 3.2 and earlier

Workarounds 🧯

There are no workarounds available to address this vulnerability.

Risk in context 🎯

The vulnerability has a CVSS score of 6.5, indicating a medium risk level. While exploitation requires authenticated access, the potential for an attacker to gain root privileges poses a significant threat to affected systems.

Fast facts ⚡

  • Vulnerability: Path traversal in Cisco Nexus Dashboard
  • CVSS Score: 6.5 (Medium)
  • Exploitation: Requires valid Administrator credentials
  • Workarounds: None available
  • Fixed Software: Upgrade to specified fixed releases

For leadership 🧭

Executive summary. A flaw in Cisco Nexus Dashboard’s backup restore feature lets someone with admin credentials escalate to root by restoring a malicious backup file, and there is no workaround. Because the fix requires an upgrade rather than a config change, this should be scheduled into the next maintenance window rather than treated as an emergency.

Why it matters:

  • The flaw sits in the backup restore path of Cisco Nexus Dashboard, a component that manages fabric-wide configuration and operational data, so root compromise here has wide reach across managed infrastructure.
  • Exploitation requires only a crafted backup file and valid Administrator credentials to trigger the path traversal, not a separate authentication bypass.
  • There are no workarounds, so risk reduction depends entirely on controlling who can restore backups and on completing the upgrade.
  • Nexus Dashboard Fabric Controller, Nexus Dashboard Insights and Nexus Dashboard Orchestrator are explicitly unaffected, so remediation effort can be focused on Nexus Dashboard itself.

Now / Next / Later:

  • Now: Restrict and audit who holds Administrator credentials and backup-restore privileges on Nexus Dashboard, and treat any unexpected backup restore request as suspect until upgraded.
  • Next: Upgrade Cisco Nexus Dashboard to release 4.1(1g) or later during your next change window, migrating off any 3.2-or-earlier or 1.0 installations as there is no workaround.
  • Later: Add a control that requires review and provenance checks on any backup file before it is restored to Nexus Dashboard, and track Nexus Dashboard patch levels alongside other network management platforms.