CVE-2025-20344

MEDIUM

Cisco Nexus Dashboard - Path Traversal

Title source: llm
STIX 2.1

Description

A vulnerability in the backup restore functionality of Cisco Nexus Dashboard could allow an authenticated, remote attacker to conduct a path traversal attack on an affected device. This vulnerability is due to insufficient validation of the contents of a backup file. An attacker with valid Administrator credentials could exploit this vulnerability by restoring a crafted backup file to an affected device. A successful exploit could allow the attacker to gain root privileges on the underlying shell on the affected device.

Scores

CVSS v3 6.5
EPSS 0.0014
EPSS Percentile 33.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-22
Status published
Products (1)
cisco/nexus_dashboard < 4.1\(1g\)
Published Aug 27, 2025
Tracked Since Feb 18, 2026