Impact
A vulnerability classified as CWE-200 exposes sensitive information through insecure handling within the Cisco Nexus Dashboard. If exploited, an attacker could access privileged data that should be protected, potentially compromising confidentiality and allowing further compromise of network resources. The weakness stems from improper protection of data in transit or storage, and does not directly enable code execution, but the disclosed information could enable social engineering, credential theft, or assistance in other attacks.
Affected Systems
The Cisco Nexus Dashboard product is affected by the hardening release issued in September 2026. No specific version ranges are provided, so all installations of Cisco Nexus Dashboard that have not yet applied the release are assumed vulnerable.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity, while the EPSS score of less than 1% suggests that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog, reducing evidence of active exploitation. Based on the nature of the software and the lack of authentication bypass, the likely attack vector is a network-based attack where the attacker sends a crafted request to the dashboard service to trigger the information leak. The vulnerability can be exploited without requiring successful privileged access, however disclosure of sensitive data can enable further attacks.
OpenCVE Enrichment