Cisco Nexus Dashboard Path Traversal Vulnerability Allowing Privilege Escalation

Vulnerability

A path traversal vulnerability has been identified in the backup restore functionality of Cisco Nexus Dashboard. This issue allows an authenticated, remote attacker to exploit insufficient validation of backup file contents. By restoring a crafted backup file, an attacker with valid Administrator credentials could gain root privileges on the underlying shell of the affected device.

Impact

Exploitation of this vulnerability could lead to unauthorized root access on the affected device's shell.

Remediation

Cisco has released software updates to address this vulnerability. Users are advised to consult the Cisco Security Advisories page for information on fixed releases and upgrade instructions.

Added: Aug 27, 2025, 5:32 PM
Updated: Aug 27, 2025, 5:32 PM

Vulnerability Rating

Custom Algorithm
spread
1.9
impact
7.5
exploitability
4.8
remediation
7.7
relevance
0.4
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.