Impact
The flaw arises from improper limitation of a pathname in Cisco Nexus Dashboard Software. This weakness, classified as CWE-22, permits an attacker to influence path resolution and potentially read or write arbitrary files on the host system. The advisory indicates that any file outside the intended scope could be accessed, thereby exposing sensitive configuration data or enabling further compromise of the device. Based on the description, it is inferred that the vulnerability could be leveraged for both confidentiality and integrity violations.
Affected Systems
Cisco Nexus Dashboard, a software component used to manage and monitor Cisco Nexus hardware. Specific affected releases are not enumerated in the advisory, so all installations of the Nexus Dashboard running prior to the September 2026 hardening release are subject to the flaw.
Risk and Exploitability
The CVSS score of 8.8 reflects a high severity potential consequence. The EPSS score of less than 1% suggests that exploitation observed in the wild is currently rare, and the vulnerability is not listed in CISA’s KEV catalog. The advisory does not specify authentication or privilege requirements, so the likely attack vector is any interface that accepts user-supplied pathnames; based on the description, it is inferred that an attacker may not need elevated privileges to exploit the flaw. Successful exploitation could allow arbitrary file reads or writes, posing a serious risk to system integrity and confidentiality.
OpenCVE Enrichment