CVE-2024-20283: Cisco Nexus Dashboard

Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability in Cisco Nexus Dashboard could allow an authenticated, remote attacker to learn cluster deployment information on an affected device. This vulnerability is due to improper access controls on a specific API endpoint. An attacker could exploit this vulnerability by sending queries to the API endpoint. A successful exploit could allow an attacker to access metrics and information about devices in the Nexus Dashboard cluster.

Affected products

  • Cisco Nexus Dashboard: before 3.1(1k) (fixed in 3.1(1k))

Published 2024-04-03. Last modified 2026-06-17.