Vulnerabilities > Cisco > Nexus Dashboard Insights

DATE CVE VULNERABILITY TITLE RISK
2024-10-02 CVE-2024-20490 Information Exposure Through Log Files vulnerability in Cisco products
A vulnerability in a logging function of Cisco Nexus Dashboard Fabric Controller (NDFC) and Cisco Nexus Dashboard Orchestrator (NDO) could allow an attacker with access to a tech support file to view sensitive information. This vulnerability exists because HTTP proxy credentials could be recorded in an internal log that is stored in the tech support file.
network
low complexity
cisco CWE-532
8.6
2024-10-02 CVE-2024-20491 Information Exposure Through Log Files vulnerability in Cisco products
A vulnerability in a logging function of Cisco Nexus Dashboard Insights could allow an attacker with access to a tech support file to view sensitive information. This vulnerability exists because remote controller credentials are recorded in an internal log that is stored in the tech support file.
network
low complexity
cisco CWE-532
8.6
2024-04-03 CVE-2024-20281 Cross-Site Request Forgery (CSRF) vulnerability in Cisco products
A vulnerability in the web-based management interface of Cisco Nexus Dashboard and Cisco Nexus Dashboard hosted services could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the web-based management interface on an affected system.
network
low complexity
cisco CWE-352
8.8