Nexus Dashboard
Vendor:
First CVE: Dec 10, 2021 · Active for 4 years
26
Total CVEs
More Total CVEs than 96% of tracked products
4.3
Avg CVEs / Year
Higher CVE frequency than 88% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 42% of tracked products
3.8%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Nexus Dashboard over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 10, 2021
4 years ago
Most Recent CVE
Apr 1, 2026
118 days ago
CVE Severity & Scoring
Nexus Dashboard26 CVEs
65%
23%
12%
All CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local5 (19.2%)
Network21 (80.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low24 (92.3%)
High2 (7.7%)
Unknown0 (0.0%)
User Interaction
None23 (88.5%)
Unknown0 (0.0%)
Required3 (11.5%)
Privileges Required
Low7 (26.9%)
High9 (34.6%)
None10 (38.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-44228CRITICAL Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect agai | Dec 10, 2021 | 10.0 | 99 | YES | YES |
CVE-2022-20858CRITICAL Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a | Jul 21, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-20857CRITICAL Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a | Jul 21, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-20861HIGH Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a | Jul 21, 2022 | 8.8 | 28 | NO | NO |
CVE-2025-20163HIGH A vulnerability in the SSH implementation of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauthenticated, remote attacker to impersonate Cisco NDFC-managed device | Jun 4, 2025 | 8.7 | 26 | NO | NO |
CVE-2024-20281HIGH A vulnerability in the web-based management interface of Cisco Nexus Dashboard and Cisco Nexus Dashboard hosted services could allow an unauthenticated, remote attacker to conduct | Apr 3, 2024 | 8.8 | 25 | NO | NO |
CVE-2026-20174MEDIUM A vulnerability in the Metadata update feature of Cisco Nexus Dashboard Insights could allow an authenticated, remote attacker to write arbitrary files to an affected system.
Th | Apr 1, 2026 | 4.9 | 24 | NO | NO |
CVE-2025-20344HIGH A vulnerability in the backup restore functionality of Cisco Nexus Dashboard could allow an authenticated, remote attacker to conduct a path traversal attack on an affected device. | Aug 27, 2025 | 7.2 | 24 | NO | NO |
CVE-2023-20014HIGH A vulnerability in the DNS functionality of Cisco Nexus Dashboard Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
This vul | Mar 1, 2023 | 7.5 | 24 | NO | NO |
CVE-2022-20907MEDIUM Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on an affected device. These vulnerabilities are due to insuffi | Jul 22, 2022 | 6.7 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (26 CVEs).
CISA KEV
1 CVE
3.8% of CVEs· 98th percentile
Metasploit
1 CVE
3.8% of CVEs· 97th percentile
Nuclei
1 CVE
3.8% of CVEs· 97th percentile
ExploitDB
1 CVE
3.8% of CVEs· 85th percentile
Social Chatter
Signals from CVEs in this product scope (26 CVEs).
Media Mentions
Signals from CVEs in this product scope (26 CVEs).
Top CNAs Publishing CVEs For Nexus Dashboard
Top CWEs
Versions
No cataloged versions.