Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-20163

Опубликовано: 04 июн. 2025
Источник: nvd
CVSS3: 8.7
EPSS Низкий

Описание

A vulnerability in the SSH implementation of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauthenticated, remote attacker to impersonate Cisco NDFC-managed devices.

This vulnerability is due to insufficient SSH host key validation. An attacker could exploit this vulnerability by performing a machine-in-the-middle attack on SSH connections to Cisco NDFC-managed devices, which could allow an attacker to intercept this traffic. A successful exploit could allow the attacker to impersonate a managed device and capture user credentials.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cisco:nexus_dashboard:*:*:*:*:*:*:*:*
Версия до 3.2\(2f\) (исключая)

EPSS

Процентиль: 8%
0.00029
Низкий

8.7 High

CVSS3

Дефекты

CWE-322

Связанные уязвимости

CVSS3: 8.7
github
8 месяцев назад

A vulnerability in the SSH implementation of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauthenticated, remote attacker to impersonate Cisco NDFC-managed devices. This vulnerability is due to insufficient SSH host key validation. An attacker could exploit this vulnerability by performing a machine-in-the-middle attack on SSH connections to Cisco NDFC-managed devices, which could allow an attacker to intercept this traffic. A successful exploit could allow the attacker to impersonate a managed device and capture user credentials.

CVSS3: 8.7
fstec
8 месяцев назад

Уязвимость реализации протокола SSH платформы управления сетевыми ресурсами Cisco Nexus Dashboard Fabric Controller (NDFC) и платформы аналитики и автоматизации работы с многооблачными сетями дата-центров Cisco Nexus Dashboard, позволяющая нарушителю выдавать себя за другого пользователя и получить зашифрованные учетные данные пользователя

EPSS

Процентиль: 8%
0.00029
Низкий

8.7 High

CVSS3

Дефекты

CWE-322