PT-2025-20253 · Cisco · Cisco Catalyst Sd-Wan Manager

Konrad Porzezynski

·

Published

2025-05-07

·

Updated

2025-08-04

·

CVE-2025-20157

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco Catalyst SD-WAN Manager versions (affected versions not specified)
Description A vulnerability in certificate validation processing could allow an unauthenticated, remote attacker to gain access to sensitive information. This issue is due to improper validation of certificates used by the Smart Licensing feature. An attacker with a privileged network position could exploit this by intercepting traffic sent over the Internet, potentially gaining access to sensitive information, including credentials used to connect to Cisco cloud services.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

BDU:2025-10319
CVE-2025-20157

Affected Products

Cisco Catalyst Sd-Wan Manager