PT-2026-29550 · Cisco · Cisco Nexus Dashboard

CVE-2026-20042

·

Publicado

2026-04-01

·

Atualizado

2026-04-01

CVSS v2.0

8.5

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Cisco Nexus Dashboard (affected versions not specified)
Description A flaw in the configuration backup feature of Cisco Nexus Dashboard could allow an attacker with the encryption password and access to backup files to access sensitive information. The issue stems from the inclusion of authentication details within the encrypted backup files. An attacker could decrypt a backup file and leverage the contained authentication details to access internal APIs, potentially leading to arbitrary command execution on the operating system as a root user.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Certificate Validation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-04791
CVE-2026-20042

Produtos afetados

Cisco Nexus Dashboard