Cisco Nexus Dashboard Insights vulnerabilities
4 known vulnerabilities affecting cisco/cisco_nexus_dashboard_insights.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2026-20174MEDIUMCVSS 4.9v2.2.2.125v2.2.2.126+13 more2026-04-01
CVE-2026-20174 [MEDIUM] CWE-22 CVE-2026-20174: A vulnerability in the Metadata update feature of Cisco Nexus Dashboard Insights could allow an auth
A vulnerability in the Metadata update feature of Cisco Nexus Dashboard Insights could allow an authenticated, remote attacker to write arbitrary files to an affected system.
This vulnerability is due to insufficient validation of the metadata update file. An attacker could exploit this vulnerability by crafting a metadata update file and manually u
cvelistv5nvd
CVE-2026-20041MEDIUMCVSS 6.1v2.2.2.125v2.2.2.126+13 more2026-04-01
CVE-2026-20041 [MEDIUM] CWE-918 CVE-2026-20041: A vulnerability in Cisco Nexus Dashboard and Cisco Nexus Dashboard Insights could allow an unauthent
A vulnerability in Cisco Nexus Dashboard and Cisco Nexus Dashboard Insights could allow an unauthenticated, remote attacker to conduct a server-side request forgery (SSRF) attack through an affected device.
This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by persuading a
cvelistv5nvd
CVE-2024-20491HIGHCVSS 8.6v2.2.2.125v2.2.2.126+12 more2024-10-02
CVE-2024-20491 [HIGH] CWE-200 CVE-2024-20491: A vulnerability in a logging function of Cisco Nexus Dashboard Insights could allow an attacker with
A vulnerability in a logging function of Cisco Nexus Dashboard Insights could allow an attacker with access to a tech support file to view sensitive information.
This vulnerability exists because remote controller credentials are recorded in an internal log that is stored in the tech support file. An attacker could exploit this vulnerability by acces
cvelistv5nvd
CVE-2024-20281HIGHCVSS 8.8v2.2.2.125v2.2.2.126+12 more2024-04-03
CVE-2024-20281 [HIGH] CWE-352 CVE-2024-20281: A vulnerability in the web-based management interface of Cisco Nexus Dashboard and Cisco Nexus Dashb
A vulnerability in the web-based management interface of Cisco Nexus Dashboard and Cisco Nexus Dashboard hosted services could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system.
This vulnerability is due to insufficient CSRF protections for the web-based management interface on an aff
cvelistv5nvd