CVE-2025-20163HIGH 8.7EPSS p28.2%
CVE-2025-20163CVE-2025-20163
Description
A vulnerability in the SSH implementation of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauthenticated, remote attacker to impersonate Cisco NDFC-managed devices.
This vulnerability is due to insufficient SSH host key validation. An attacker could exploit this vulnerability by performing a machine-in-the-middle attack on SSH connections to Cisco NDFC-managed devices, which could allow an attacker to intercept this traffic. A successful exploit could allow the attacker to impersonate a managed device and capture user credentials.
Scoring
| CVSS 3.1 | 8.7 (HIGH) |
| Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N |
| EPSS | 0.36% probability of exploitation · percentile 28.2% · 2026-06-18T12:00:27Z |
| Published | 2025-06-04 |
| Last modified | 2025-07-22 |
Underlying weaknesses· 1
References
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Key Exchange without Entity Authenticationcwe-322 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.