{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-07T00:08:44.559","vulnerabilities":[{"cve":{"id":"CVE-2025-20163","sourceIdentifier":"psirt@cisco.com","published":"2025-06-04T17:15:26.037","lastModified":"2025-07-22T16:58:34.137","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability in the SSH implementation of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauthenticated, remote attacker to impersonate Cisco NDFC-managed devices.\r\n\r\nThis vulnerability is due to insufficient SSH host key validation. An attacker could exploit this vulnerability by performing a machine-in-the-middle attack on SSH connections to Cisco NDFC-managed devices, which could allow an attacker to intercept this traffic. A successful exploit could allow the attacker to impersonate a managed device and capture user credentials."},{"lang":"es","value":"Una vulnerabilidad en la implementación SSH de Cisco Nexus Dashboard Fabric Controller (NDFC) podría permitir que un atacante remoto no autenticado se haga pasar por dispositivos administrados por Cisco NDFC. Esta vulnerabilidad se debe a una validación insuficiente de la clave de host SSH. Un atacante podría explotar esta vulnerabilidad mediante un ataque de máquina en el medio (MCI) en conexiones SSH a dispositivos administrados por Cisco NDFC, lo que podría permitirle interceptar este tráfico. Una explotación exitosa podría permitir al atacante hacerse pasar por un dispositivo administrado y obtener las credenciales del usuario."}],"metrics":{"cvssMetricV31":[{"source":"psirt@cisco.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":5.8}]},"weaknesses":[{"source":"psirt@cisco.com","type":"Secondary","description":[{"lang":"en","value":"CWE-322"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:nexus_dashboard:*:*:*:*:*:*:*:*","versionEndExcluding":"3.2\\(2f\\)","matchCriteriaId":"5913A4DA-CFB5-4FD1-8FD8-A481E5C384C5"}]}]}],"references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ndfc-shkv-snQJtjrp","source":"psirt@cisco.com","tags":["Vendor Advisory"]}]}}]}