Impact
The vulnerability in Cisco Nexus Dashboard is an improper access control flaw that can allow an attacker to gain unauthorized privileged access to the system. This weakness is classified as CWE-284 and may enable escalation of privileges or bypass of security controls, potentially compromising the confidentiality, integrity, and availability of the managed network infra.
Affected Systems
Affected vendors include Cisco, specifically the Cisco Nexus Dashboard product line. No specific version information is provided in the advisory, so the issue is considered present in all releases prior to the September 2026 hardening update.
Risk and Exploitability
The CVSS score of 9.9 indicates critical severity. The EPSS score of less than 1% suggests a very low probability of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote access over the network where authentication or authorization checks are improperly enforced, which is inferred from the nature of an access control flaw and the absence of local-only qualifiers in the description. Excessive risk remains if systems remain unpatched, especially for administrators or services exposed to untrusted networks.
OpenCVE Enrichment