Vulnerabilities > Cisco > Nexus Dashboard Fabric Controller

DATE CVE VULNERABILITY TITLE RISK
2024-04-03 CVE-2024-20281 Cross-Site Request Forgery (CSRF) vulnerability in Cisco products
A vulnerability in the web-based management interface of Cisco Nexus Dashboard and Cisco Nexus Dashboard hosted services could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the web-based management interface on an affected system.
network
low complexity
cisco CWE-352
8.8
2024-04-03 CVE-2024-20348 Path Traversal vulnerability in Cisco Nexus Dashboard Fabric Controller 12.1.3/12.1.3B
A vulnerability in the Out-of-Band (OOB) Plug and Play (PnP) feature of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauthenticated, remote attacker to read arbitrary files. This vulnerability is due to an unauthenticated provisioning web server.
network
low complexity
cisco CWE-22
7.5