Database/Control plane, storage & DevOps
Cisco Nexus Dashboard (web UI / CSRF): One of a batch of unauthenticated flaws in Nexus Dashboard that together allow
Impact
One of a batch of unauthenticated flaws in Nexus Dashboard that together allow remote command execution, reading and uploading container images, and CSRF. Nexus Dashboard is the pane of glass over your whole data-center fabric, so an attacker who lands here can push configuration and container workloads to every managed switch. Uploading a container image is the persistence path — it survives the dashboard being patched.
Who can reach it
Unauthenticated, remote to the Nexus Dashboard web interface. CSRF variant needs an admin to visit an attacker page while logged in.
What to do
Upgrade the Nexus Dashboard cluster software. Application upgrade, no switch reload; the managed fabric keeps forwarding throughout. Re-verify every managed device's running image afterwards, since image upload was in scope.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.