BlackTree Security · Infrastructure · Automation · AI

Cisco Found a Missing Login Check in Its Data-Centre Control Panel

The software coordinating a data centre deserves scrutiny before an attacker proves why. Cisco Nexus Dashboard hardening now addresses six vulnerability classes, including a missing authentication check for a critical function. Cisco reports no known malicious use, but the significance of a management-plane weakness does not depend on waiting for a public incident.

The 16 September bulletin groups defects by class, scoring each group’s worst member. These identifiers are not a count of individual bugs.

Six identifiers do not mean six identical attack paths

IdentifierMaximum CVSSClassPrivileges in published maximum-severity vector
CVE-2026-203229.9Improper access controlLow
CVE-2026-203259.9Command or code injectionLow
CVE-2026-203269.8Missing authenticationNone
CVE-2026-203608.8Information exposureLow
CVE-2026-203618.8SQL injectionLow
CVE-2026-764098.8Path traversalLow
Classes and vectors checked against the six original CNA records linked below. All maximum-severity vectors are network-based with no user interaction.

The original CNA records expose a useful distinction: the published missing-authentication vector requires no privileges; the other five require low privileges. These are worst-member vectors, not complete prerequisites for every grouped defect. Treating all six classes as unauthenticated root execution would overstate the evidence.

One remediation table applies to all six identifiers

Nexus Dashboard branchRemediation
4.2 and earlierMigrate to a fixed release
4.3First fixed release 4.3.1.175
Use a compatible maintained fixed release and check upgrade prerequisites.

All six classes share no-workaround and no-known-exploitation guidance. Cisco says configuration does not remove affected software from scope. No credible public exploit was verified. Access restrictions are not the product fix.

Make the change measurable before calling it complete

BlackTree recommends treating the dashboard as a control-plane dependency in the change process. Agree who owns availability, who verifies the resulting build and who reviews anything suspicious found during the work. A patch ticket should distinguish a technical upgrade result from an incident-response conclusion.

  • Identify every deployment. Record the branch, running build, administrative reachability and owner. Include test or recovery deployments with real infrastructure access.
  • Check the migration path. Assess compatibility, dependencies, backups and the vendor’s upgrade procedure before replacing an older branch.
  • Verify the running version afterwards. Confirm the actual software on the deployment rather than relying only on the success of an installation task.
  • Review privileged connections. Document which administrators, automation accounts and networks should reach the management surface. Remove unnecessary access through the normal change process.
  • Test useful operation and monitoring. Confirm expected management functions, recovery access and central logging after the upgrade.
  • Escalate evidence, not assumptions. Unexpected accounts, files or changes deserve investigation. The bulletin alone does not prove that a particular deployment was compromised.

Related BlackTree coverage of Nexus 9000 switch code execution concerns a different product and attack path. A completed switch remediation is not evidence that Nexus Dashboard has received this hardening release.

The practical question is not whether the bulletin has six red scores. It is whether the system trusted to coordinate infrastructure is running the fixed software, with an accountable owner and a verified result.

Sources

Original CNA records, published and last updated on 16 September 2026: access control at 20:02:56 UTC; injection at 20:06:50 UTC; missing authentication at 20:02:33 UTC; information exposure at 20:13:40 UTC; SQL injection at 20:08:08 UTC; and path traversal at 20:10:07 UTC. Madrid times are two hours later. Clocks are shown to the second, omitting record milliseconds.

Leave a Reply

Your email address will not be published. Required fields are marked *