GPU VulnDB

Database/Control plane, storage & DevOps

Cisco Nexus Dashboard (web UI / CSRF): One of a batch of unauthenticated flaws in Nexus Dashboard that together allow

CVE-2022-20861Control plane, storage & DevOpscurated

Impact

One of a batch of unauthenticated flaws in Nexus Dashboard that together allow remote command execution, reading and uploading container images, and CSRF. Nexus Dashboard is the pane of glass over your whole data-center fabric, so an attacker who lands here can push configuration and container workloads to every managed switch. Uploading a container image is the persistence path — it survives the dashboard being patched.

Who can reach it

Unauthenticated, remote to the Nexus Dashboard web interface. CSRF variant needs an admin to visit an attacker page while logged in.

What to do

Upgrade the Nexus Dashboard cluster software. Application upgrade, no switch reload; the managed fabric keeps forwarding throughout. Re-verify every managed device's running image afterwards, since image upload was in scope.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.