PT-2025-20277 · Cisco · Cisco Ios Xe

Published

2025-05-07

·

Updated

2025-08-05

·

CVE-2025-20214

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco IOS XE Software (affected versions not specified)
Description A vulnerability in the Network Configuration Access Control Module (NACM) could allow an authenticated, remote attacker to obtain unauthorized read access to configuration or operational data. This issue exists due to incorrect filtering of results caused by a change in inner API call behavior. An attacker could exploit this by using NETCONF, RESTCONF, or gRPC Network Management Interface (gNMI) protocols to query data on paths that may have been denied by the NACM configuration, potentially accessing restricted data.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

IDOR

Weakness Enumeration

Related Identifiers

CVE-2025-20214

Affected Products

Cisco Ios Xe