{"id":"CVE-2026-20325","title":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard&nbsp;engineering team has conducted a comprehensive internal security review","summary":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard&nbsp;engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release…","severity":"critical","cvss":9.9,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","cwe":["CWE-77"],"vendor":"Cisco","product":"Cisco Nexus Dashboard","affected":["nexus_dashboard 2.1(1d)","nexus_dashboard 2.1(1e)","nexus_dashboard 2.1(2d)","nexus_dashboard 2.2(1h)","nexus_dashboard 2.2(1e)","nexus_dashboard 2.2(2d)","nexus_dashboard 2.1(2f)","nexus_dashboard 2.3(1c)","nexus_dashboard 2.3(2b)","nexus_dashboard 2.3(2c)","nexus_dashboard 2.3(2d)","nexus_dashboard 2.3(2e)","nexus_dashboard 3.0(1f)","nexus_dashboard 3.0(1i)","nexus_dashboard 3.1(1k)","nexus_dashboard 3.1(1l)","nexus_dashboard 3.2(1e)","nexus_dashboard 3.2(1i)","nexus_dashboard 3.3(1a)","nexus_dashboard 3.3(1b)","nexus_dashboard 3.3(2b)","nexus_dashboard 4.0(1i)","nexus_dashboard 3.3(2g)","nexus_dashboard 3.2(2f)","nexus_dashboard 3.2(2g)","nexus_dashboard 3.2(2m)","nexus_dashboard 3.1(1n)","nexus_dashboard 4.1(1g)","nexus_dashboard 4.2.1"],"published":"2026-09-16","updated":"2026-09-18","sourceUpdated":"2026-09-18T15:17:07.450","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-20325","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-ndw1-psFvnrg","label":"psirt@cisco.com"},{"url":"https://software.cisco.com"}],"tags":["nvd","cve.org","csaf","vendor-advisory","cisco"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-18T03:55:50.558437Z"},"epss":0.0034,"epssPercentile":0.27493,"ingestedAt":"2026-09-16T16:37:52.186Z","slug":"CVE-2026-20325","body":"## Overview\n\nAs part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard&nbsp;engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20325 are related to improper neutralization of special elements used in a command issue that are grouped under the Common Weakness Enumeration (CWE) CWE-77.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **cisco-sa-hardening-ndw1-psFvnrg** · Cisco · affected: Cisco Nexus Dashboard (40 versions) · updated 2026-09-16 · [advisory](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-ndw1-psFvnrg)","depth":"midnight","depthScore":55,"depthScoreParts":{"impact":54.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}