216.73.216.6

CVE-2025-20122

· Published 07/05/2025 18:15 · Modified 07/05/2025 18:15

Labels: CVE-2025-20122 2025-05-07CVE-2025-20122CWE-300[email protected]

Essential information

Published
07/05/2025 18:15
Modified
07/05/2025 18:15
Author
Creator
CVSS
7.8 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, local attacker to gain privileges of the root user on the underlying operating system. This vulnerability is due to insufficient input validation. An authenticated attacker with read-only privileges on the SD-WAN Manager system could exploit this vulnerability by sending a crafted request to the CLI of the SD-WAN Manager. A successful exploit could allow the attacker to gain root privileges on the underlying operating system.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
cisco / catalyst sd-wan manager cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:*
cisco / sd-wan vmanage cpe:2.3:a:cisco:sd-wan_vmanage:*:*:*:*:*:*:*:*

References