PT-2025-16790 · Cisco · Cisco Secure Network Analytics

Published

2025-04-16

·

Updated

2025-04-16

·

CVE-2025-20178

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco Secure Network Analytics (affected versions not specified)
Description A vulnerability in the web-based management interface could allow an authenticated, remote attacker with valid administrative credentials to execute arbitrary commands as root on the underlying operating system. This issue is due to insufficient integrity checks within device backup files. An attacker could exploit this by crafting a malicious backup file and restoring it to an affected device, potentially obtaining shell access on the underlying operating system with the privileges of root.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Improper Verification of Cryptographic Signature

Weakness Enumeration

Related Identifiers

BDU:2025-05024
CVE-2025-20178

Affected Products

Cisco Secure Network Analytics