PT-2025-8733 · Cisco · Cisco Apic

Jean-Michel Huguet

+1

·

Published

2025-02-26

·

Updated

2025-07-31

·

CVE-2025-20118

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco APIC (affected versions not specified)
Description A vulnerability in the implementation of internal system processes could allow an authenticated, local attacker to access sensitive information on an affected device. The attacker must have valid administrative credentials to exploit this issue. This vulnerability is due to insufficient masking of sensitive information displayed through system CLI commands. An attacker could exploit this by using reconnaissance techniques at the device CLI, potentially accessing sensitive information that could be used for additional attacks.
Recommendations Update to a version of Cisco APIC that includes the software updates released by Cisco to address this vulnerability.

Fix

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-05654
CVE-2025-20118

Affected Products

Cisco Apic