Cisco NX-OS Software Sensitive... Note

Cisco NX-OS Software Sensitive Log Information Disclosure Vulnerability

A vulnerability exists in the logging feature of specific Cisco NX-OS and UCS devices. This flaw could permit an authenticated local attacker to access sensitive information. The issue stems from the improper logging of this sensitive data. Exploitation requires the attacker to gain access to the device's file system. On Nexus devices, file system access is necessary to retrieve log files. For UCS Fabric Interconnects, an administrator must generate and download a tech support file to expose the logs. These log files contain sensitive information, potentially including stored credentials. Cisco has released software updates to resolve this vulnerability. No workarounds are available to mitigate this issue. The security impact rating for this vulnerability is Medium, identified by CVE-2025-20290.