Executive brief
Cisco Nexus Dashboard is a centralized management and monitoring platform used to manage Cisco network infrastructure. This advisory addresses multiple internally discovered vulnerabilities related to improper access control, command injection, missing authentication, information exposure, SQL injection, and path traversal. These flaws could allow authenticated or unauthenticated attackers to access sensitive data, execute commands, or bypass security controls depending on the specific vulnerability.
Technical details
This advisory groups six distinct vulnerabilities under a single hardening release affecting Cisco Nexus Dashboard. The vulnerabilities span multiple CWE categories: CWE-284 (improper access control), CWE-77 (command injection), CWE-306 (missing authentication), CWE-200 (information exposure), CWE-89 (SQL injection), and CWE-22 (path traversal). The vulnerabilities were discovered through internal security testing and AI-assisted analysis. Affected versions are 4.2 and earlier; fixes are available starting with version 4.3.1.175. No workarounds are available, and there is no evidence of active exploitation in the wild.
Affected products
- Cisco Nexus Dashboard 4.2 and earlier
Timeline
- 2026-09-16: disclosed