Cisco Nexus Dashboard backup files include embedded authentication credentials. If an attacker obtains a valid backup file and its encryption password, they can decrypt the backup and use the credentials to access internal APIs. This access allows execution of arbitrary commands as root on the underlying system.
There are no workarounds; Cisco released fixed software versions that remove or protect these credentials in backups. Operators must treat any exposed backups and passwords as compromised, rotate credentials, revoke API sessions, and upgrade to the fixed release to prevent root-level compromise through backup file decryption.