Cisco Nexus Dashboard and Nexus Dashboard Insights Server-Side Request Forgery Vulnerability — CISCO-SA-ND-SSRF-NAEN4O7R
Cisco · Cisco · CISCO-SA-ND-SSRF-NAEN4O7R
ID
CISCO-SA-ND-SSRF-NAEN4O7R
CISCO-SA-ND-SSRF-NAEN4O7R
Date
Activity
Source
Cisco
Cisco
Vendor
Cisco
Cisco
Threat
medium
medium
Summary
A vulnerability in Cisco Nexus Dashboard and Cisco Nexus Dashboard Insights could allow an unauthenticated, remote attacker to conduct a server-side request forgery (SSRF) attack through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by persuading an authenticated user of the device management interface to click a…
Product
Cisco Nexus Dashboard and Nexus Dashboard Insights Server-Side Request Forgery
What to do
General, cautious steps (verify details in the official source):
- Review exposure and plan remediation based on risk and environment.
- Identify affected product versions in your inventory and verify whether you are impacted.
- Apply vendor patches/updates or recommended mitigations as soon as available.
- Read the official advisory for exact affected versions and remediation steps.