CVE-2022-20861: Cisco Nexus Dashboard Unauthorized Access Vulnerabilities
Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information about these vulnerabilities, see the Details section of this advisory.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Cisco Nexus Dashboard vulnerability?
The vulnerability ID for this Cisco Nexus Dashboard vulnerability is CVE-2022-20861.
What is the severity rating of CVE-2022-20861?
The severity rating of CVE-2022-20861 is critical.
What can an unauthenticated remote attacker do with this vulnerability?
An unauthenticated remote attacker can execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack using this vulnerability.
Which versions of Cisco Nexus Dashboard are affected?
Cisco Nexus Dashboard versions between 1.1 and 2.2(1e) are affected by this vulnerability.
Where can I find more information about these vulnerabilities?
You can find more information about these vulnerabilities in the details section of the Cisco Security Advisory at the following link: [Cisco Security Advisory](https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ndb-mhcvuln-vpsBPJ9y)