Cisco Nexus Dashboard
cpe:2.3:a:cisco:nexus_dashboard:*:*:*:*:*:*:*
A path traversal vulnerability has been identified in the backup restore functionality of Cisco Nexus Dashboard. This issue allows an authenticated, remote attacker to exploit insufficient validation of backup file contents. By restoring a crafted backup file, an attacker with valid Administrator credentials could gain root privileges on the underlying shell of the affected device.
Exploitation of this vulnerability could lead to unauthorized root access on the affected device's shell.
Cisco has released software updates to address this vulnerability. Users are advised to consult the Cisco Security Advisories page for information on fixed releases and upgrade instructions.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.