PT-2026-29550 · Cisco · Cisco Nexus Dashboard
Published
2026-04-01
·
Updated
2026-04-01
·
CVE-2026-20042
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Nexus Dashboard (affected versions not specified)
Description
A flaw in the configuration backup feature of Cisco Nexus Dashboard could allow an attacker with the encryption password and access to backup files to access sensitive information. The issue stems from the inclusion of authentication details within the encrypted backup files. An attacker could decrypt a backup file and leverage the contained authentication details to access internal APIs, potentially leading to arbitrary command execution on the operating system as a root user.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Nexus Dashboard