Vulnerabilities · 167 days ago
Cisco Nexus Dashboard Insights has an authenticated arbitrary file write vulnerability in its Metadata update feature. An attacker with valid admin credentials can upload crafted metadata files to write root-level files on the system. Separately, Cisco Nexus Dashboard has a user-interactive SSRF vulnerability that can coerce authenticated users into sending attacker-controlled network requests.
These vulnerabilities together increase the risk of post-authentication compromise. The unified Nexus Dashboard image includes Insights, so upgrading to the fixed Nexus Dashboard release addresses both issues. No workarounds exist, making patching the only reliable remediation. This is especially critical for air-gapped or disconnected environments where manual metadata uploads occur.
1 source covering this story
Cisco Security Advisory: Cisco Nexus Dashboard Insights Arbitrary File Write Vulnerability
A vulnerability in the Metadata update feature of Cisco Nexus Dashboard Insights could allow an authenticated, remote attacker to write arbitrary files to an affected system.
A vulnerability in Cisco Nexus Dashboard and Cisco Nexus Dashboard Insights could allow an unauthenticated, remote attacker to conduct a server-side request forgery (SSRF) attack through an affected device.
Part of the PlainSec briefing for 2026-04-02