PT-2025-20246 · Cisco · Cisco Catalyst Sd-Wan Manager

Andrew Kim

·

Published

2025-05-07

·

Updated

2025-05-07

·

CVE-2025-20122

CVSS v3.1
7.8
VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Name of the Vulnerable Software and Affected Versions:

Cisco Catalyst SD-WAN Manager (affected versions not specified)

Description:

A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager could allow an authenticated, local attacker to gain privileges of the root user on the underlying operating system. This issue is due to insufficient input validation, allowing an attacker with read-only privileges to exploit the vulnerability by sending a crafted request to the CLI. A successful exploit could allow the attacker to gain root privileges on the underlying operating system.

Recommendations:

At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2025-20122

Affected Products

Cisco Catalyst Sd-Wan Manager