PT-2025-20275 · Cisco · Cisco Catalyst Center
Simen Abrahamsen
+1
·
Published
2025-05-07
·
Updated
2025-08-13
·
CVE-2025-20210
CVSS v3.1
7.3
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Cisco Catalyst Center (affected versions not specified)
Description
A vulnerability in the management API could allow an unauthenticated, remote attacker to read and modify the outgoing proxy configuration settings. This issue is due to the lack of authentication in an API endpoint. An attacker could exploit this by sending a request to the affected API, potentially disrupting internet traffic or intercepting outbound internet traffic.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Catalyst Center