Vulnslist

Cisco vulnerabilities by product, model, software, and advisory.

CVE-2025-20122

A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, local attacker to gain privileges of the root user on the underlying operating system. This vulnerability is due to insufficient input validation. An authenticated attacker with read-only privileges on the SD-WAN Manager system could exploit this vulnerability by sending a crafted request to the CLI of the SD-WAN Manager. A successful exploit could allow the attacker to gain root privileges on the underlying operating system.

SeverityHIGH
CVSS7.8
CWECWE-300
KEV
Published
Modified

Related Products

Product Advisory Evidence
Cisco SD-WAN vManage cisco-sa-sdwan-priviesc-WCk7bmmt Cisco OpenVuln
Cisco Catalyst SD-WAN Manager cisco-sa-sdwan-priviesc-WCk7bmmt Cisco OpenVuln
Cisco Catalyst SD-WAN cisco-sa-sdwan-priviesc-WCk7bmmt Cisco OpenVuln