ZeroHour

CVE-2026-20325

moderate1

Authenticated Command Injection in Cisco Nexus Dashboard

CVSS 3.1
9.9 critical
EPSS
Published
()
Modified
AI analysis

Cisco Nexus Dashboard contains a command injection vulnerability (CWE-77) in which special elements in user-controlled input are improperly neutralized before being passed to an operating system command. An attacker needs network access to the management interface and a valid low-privileged account, with no user interaction required; the changed scope in the CVSS vector indicates successful commands can impact components beyond the vulnerable one. A successful attacker gains the ability to run arbitrary commands in the context of the affected service, with high impact on confidentiality, integrity, and availability, potentially compromising the Nexus Dashboard appliance and the fabric management functions it hosts. Any organization running Cisco Nexus Dashboard to manage its data center switching estate is in scope. The flaw was found by Cisco's internal review as part of a software hardening release; there is no public proof-of-concept, it is not in CISA KEV, and no exploitation is currently known.

What to do: Upgrade Nexus Dashboard to the software hardening release identified in Cisco's advisory (check the Cisco PSIRT bulletin for the exact fixed versions), as the flaw was fixed proactively. Until patched, restrict access to the Nexus Dashboard management interface to trusted admin networks and audit low-privileged user accounts that could reach the affected functionality. Monitor Cisco PSIRT and CISA KEV for updates, since low-privilege authenticated command injection with these CVSS metrics is likely to draw exploit research once details surface.

Affected
Cisco Nexus Dashboard
Estimated exposure
moderate≈10,000–50,000 Nexus Dashboard deployments worldwide, with only management-plane exposure typically (mostly internal networks) — Estimated from Cisco Nexus Dashboard's position as Cisco's consolidated management platform (Insights, Orchestrator, Fabric Controller) shipped across its very large enterprise data center switching install base, one appliance per data…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20325 are related to improper neutralization of special elements used in a command issue that are grouped under the Common Weakness Enumeration (CWE) CWE-77.

Weakness
CWE-77
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

Cisco warns CVE-2026-76460 (CVSS 10.0), an unauthenticated ISE auth bypass leading to root command execution, is under active exploitation and was added to CISA's KEV.

Cisco warned that CVE-2026-76460 (CVSS 10.0), an insufficient-authentication flaw in an Identity Services Engine (ISE) API endpoint, is being actively exploited by unauthenticated remote attackers and can yield root-privilege command execution on ISE and ISE-PIC regardless of configuration. Fixes shipped across ISE 3.1 through 3.5 patch branches; Cisco advised reviewing access.log for unexpected usernames (e.g., "dummyuser"), re-imaging affected nodes, and using iACLs, since no workarounds exist. CISA added the flaw to its KEV catalog on September 16, 2026, requiring FCEB agencies to patch by September 19. Cisco simultaneously issued 77 new CVEs, 41 affecting ISE and 28 affecting Secure Firewall products, days after confirming active exploitation of CVE-2026-76461 in Secure Email Gateway.