Changeflow GovPing Data Privacy & Cybersecurity Cisco Nexus Vulnerabilities Allow File Manipula...
Routine Notice Added Final

Cisco Nexus Vulnerabilities Allow File Manipulation, Data Disclosure

Favicon for wid.cert-bund.de CERT-Bund Security Advisories
Published April 1st, 2026
Detected April 2nd, 2026
Email

Summary

CERT-Bund released security advisory WID-SEC-2026-0955 identifying multiple vulnerabilities in Cisco Nexus Dashboard (<4.2) and Cisco Nexus Dashboard Insights. The vulnerabilities have a CVSS Base Score of 6.5 (Medium) and enable remote attackers to manipulate files or disclose confidential information. Mitigation measures are available.

What changed

CERT-Bund identified multiple vulnerabilities in Cisco Nexus Dashboard and Insights, affecting versions prior to 4.2. The vulnerabilities carry a CVSS Base Score of 6.5 (Medium) and enable remote attackers to manipulate files or disclose confidential information, potentially facilitating further attacks.

Organizations using Cisco Nexus Dashboard and Insights should update to version 4.2 or later and implement available mitigations to address these vulnerabilities.

What to do next

  1. Update Cisco Nexus Dashboard to version 4.2 or later
  2. Implement available mitigations for affected systems
  3. Review and monitor for indicators of compromise

Source document (simplified)

[WID-SEC-2026-0955] Cisco Nexus Dashboard und Insights: Mehrere Schwachstellen CVSS Base Score 6.5 (mittel) CVSS Temporal Score 5.7 (mittel) Remoteangriff ja Datum 01.04.2026 Stand 02.04.2026 Mitigation ja

Betroffene Systeme

Betriebssystem

  • CISCO Appliance

Produktbeschreibung

Cisco Nexus Dashboard ist ein Dashboard für Rechenzentren zur Verwaltung von Hybrid-Cloud-Netzwerken.

Produkte

01.04.2026
- Cisco Nexus Dashboard <4.2

  • Cisco Nexus Dashboard Insights

Angriff

Angriff

Ein kann mehrere Schwachstellen in Cisco Nexus Dashboard und Insights ausnutzen, um Dateien zu manipulieren oder vertrauliche Informationen offenzulegen, was möglicherweise weitere Angriffe ermöglicht. CVE Informationen Versionshistorie Feedback zum Advisory geben

Source

Analysis generated by AI. Source diff and links are from the original.

Classification

Agency
CERT-Bund
Published
April 1st, 2026
Instrument
Notice
Legal weight
Non-binding
Stage
Final
Change scope
Minor
Document ID
WID-SEC-2026-0955

Who this affects

Applies to
Technology companies Government agencies Telecommunications firms
Industry sector
5112 Software & Technology 5170 Telecommunications 9211 Government & Public Administration
Activity scope
Network Security Vulnerability Management
Threshold
Cisco Nexus Dashboard <4.2, Cisco Nexus Dashboard Insights
Geographic scope
Germany DE

Taxonomy

Primary area
Cybersecurity
Operational domain
IT Security
Topics
Data Privacy Telecommunications

Get Data Privacy & Cybersecurity alerts

Weekly digest. AI-summarized, no noise.

Free. Unsubscribe anytime.

Get alerts for this source

We'll email you when CERT-Bund Security Advisories publishes new changes.

Optional. Personalizes your daily digest.

Free. Unsubscribe anytime.