Cisco Nexus Dashboard Insights has an authenticated arbitrary file write vulnerability in its Metadata update feature. An attacker with valid admin credentials can upload crafted metadata files to write root-level files on the system. Separately, Cisco Nexus Dashboard has a user-interactive SSRF vulnerability that can coerce authenticated users into sending attacker-controlled network requests.
These vulnerabilities together increase the risk of post-authentication compromise. The unified Nexus Dashboard image includes Insights, so upgrading to the fixed Nexus Dashboard release addresses both issues. No workarounds exist, making patching the only reliable remediation. This is especially critical for air-gapped or disconnected environments where manual metadata uploads occur.