PT-2025-20275 · Cisco · Cisco Catalyst Center

Simen Abrahamsen

+1

·

Published

2025-05-07

·

Updated

2025-08-13

·

CVE-2025-20210

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Cisco Catalyst Center (affected versions not specified)
Description A vulnerability in the management API could allow an unauthenticated, remote attacker to read and modify the outgoing proxy configuration settings. This issue is due to the lack of authentication in an API endpoint. An attacker could exploit this by sending a request to the affected API, potentially disrupting internet traffic or intercepting outbound internet traffic.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-20210

Affected Products

Cisco Catalyst Center