cve-2025-20122
Vulnerability from cvelistv5
Published
2025-05-07 17:18
Modified
2025-05-08 03:56
Severity ?
EPSS score ?
Summary
Cisco Catalyst SD-WAN Manager Privilege Escalation Vulnerability
References
Impacted products
▼ | Vendor | Product |
---|---|---|
Cisco | Cisco Catalyst SD-WAN Manager |
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2025-20122", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2025-05-07T00:00:00+00:00", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-05-08T03:56:28.948Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "defaultStatus": "unknown", "product": "Cisco Catalyst SD-WAN Manager", "vendor": "Cisco", "versions": [ { "status": "affected", "version": "20.1.12" }, { "status": "affected", "version": "19.2.1" }, { "status": "affected", "version": "18.4.4" }, { "status": "affected", "version": "18.4.5" }, { "status": "affected", "version": "20.1.1.1" }, { "status": "affected", "version": "20.1.1" }, { "status": "affected", "version": "19.3.0" }, { "status": "affected", "version": "19.2.2" }, { "status": "affected", "version": "19.2.099" }, { "status": "affected", "version": "18.3.6" }, { "status": "affected", "version": "18.3.7" }, { "status": "affected", "version": "19.2.0" }, { "status": "affected", "version": "18.3.8" }, { "status": "affected", "version": "19.0.0" }, { "status": "affected", "version": "19.1.0" }, { "status": "affected", "version": "18.4.302" }, { "status": "affected", "version": "18.4.303" }, { "status": "affected", "version": "19.2.097" }, { "status": "affected", "version": "19.2.098" }, { "status": "affected", "version": "17.2.10" }, { "status": "affected", "version": "18.3.6.1" }, { "status": "affected", "version": "19.0.1a" }, { "status": "affected", "version": "18.2.0" }, { "status": "affected", "version": "18.4.3" }, { "status": "affected", "version": "18.4.1" }, { "status": "affected", "version": "17.2.8" }, { "status": "affected", "version": "18.3.3.1" }, { "status": "affected", "version": "18.4.0" }, { "status": "affected", "version": "18.3.1" }, { "status": "affected", "version": "17.2.6" }, { "status": "affected", "version": "17.2.9" }, { "status": "affected", "version": "18.3.4" }, { "status": "affected", "version": "17.2.5" }, { "status": "affected", "version": "18.3.1.1" }, { "status": "affected", "version": "18.3.5" }, { "status": "affected", "version": "18.4.0.1" }, { "status": "affected", "version": "18.3.3" }, { "status": "affected", "version": "17.2.7" }, { "status": "affected", "version": "17.2.4" }, { "status": "affected", "version": "18.3.0" }, { "status": "affected", "version": "19.2.3" }, { "status": "affected", "version": "18.4.501_ES" }, { "status": "affected", "version": "20.3.1" }, { "status": "affected", "version": "20.1.2" }, { "status": "affected", "version": "19.2.929" }, { "status": "affected", "version": "19.2.31" }, { "status": "affected", "version": "20.3.2" }, { "status": "affected", "version": "19.2.32" }, { "status": "affected", "version": "20.3.2_925" }, { "status": "affected", "version": "20.3.2.1" }, { "status": "affected", "version": "20.3.2.1_927" }, { "status": "affected", "version": "18.4.6" }, { "status": "affected", "version": "20.1.2_937" }, { "status": "affected", "version": "20.4.1" }, { "status": "affected", "version": "20.3.2_928" }, { "status": "affected", "version": "20.3.2_929" }, { "status": "affected", "version": "20.4.1.0.1" }, { "status": "affected", "version": "20.3.2.1_930" }, { "status": "affected", "version": "19.2.4" }, { "status": "affected", "version": "20.5.0.1.1" }, { "status": "affected", "version": "20.4.1.1" }, { "status": "affected", "version": "20.3.3" }, { "status": "affected", "version": "19.2.4.0.1" }, { "status": "affected", "version": "20.3.2_937" }, { "status": "affected", "version": "20.3.3.1" }, { "status": "affected", "version": "20.5.1" }, { "status": "affected", "version": "20.1.3" }, { "status": "affected", "version": "20.3.3.0.4" }, { "status": "affected", "version": "20.3.3.1.2" }, { "status": "affected", "version": "20.3.3.1.1" }, { "status": "affected", "version": "20.4.1.2" }, { "status": "affected", "version": "20.3.3.0.2" }, { "status": "affected", "version": "20.4.1.1.5" }, { "status": "affected", "version": "20.4.1.0.01" }, { "status": "affected", "version": "20.4.1.0.02" }, { "status": "affected", "version": "20.3.3.1.7" }, { "status": "affected", "version": "20.3.3.1.5" }, { "status": "affected", "version": "20.5.1.0.1" }, { "status": "affected", "version": "20.3.3.1.10" }, { "status": "affected", "version": "20.3.3.0.8" }, { "status": "affected", "version": "20.4.2" }, { "status": "affected", "version": "20.4.2.0.1" }, { "status": "affected", "version": "20.3.4" }, { "status": "affected", "version": "20.3.3.0.14" }, { "status": "affected", "version": "19.2.4.0.8" }, { "status": "affected", "version": "19.2.4.0.9" }, { "status": "affected", "version": "20.3.4.0.1" }, { "status": "affected", "version": "20.3.2.0.5" }, { "status": "affected", "version": "20.6.1" }, { "status": "affected", "version": "20.5.1.0.2" }, { "status": "affected", "version": "20.3.3.0.17" }, { "status": "affected", "version": "20.6.1.1" }, { "status": "affected", "version": "20.6.0.18.3" }, { "status": "affected", "version": "20.3.2.0.6" }, { "status": "affected", "version": "20.6.0.18.4" }, { "status": "affected", "version": "20.4.2.0.2" }, { "status": "affected", "version": "20.3.3.0.16" }, { "status": "affected", "version": "20.3.4.0.5" }, { "status": "affected", "version": "20.6.1.0.1" }, { "status": "affected", "version": "20.3.4.0.6" }, { "status": "affected", "version": "20.6.2" }, { "status": "affected", "version": "20.7.1EFT2" }, { "status": "affected", "version": "20.3.4.0.9" }, { "status": "affected", "version": "20.3.4.0.11" }, { "status": "affected", "version": "20.4.2.0.4" }, { "status": "affected", "version": "20.3.3.0.18" }, { "status": "affected", "version": "20.7.1" }, { "status": "affected", "version": "20.6.2.1" }, { "status": "affected", "version": "20.3.4.1" }, { "status": "affected", "version": "20.5.1.1" }, { "status": "affected", "version": "20.4.2.1" }, { "status": "affected", "version": "20.4.2.1.1" }, { "status": "affected", "version": "20.3.4.1.1" }, { "status": "affected", "version": "20.3.813" }, { "status": "affected", "version": "20.3.4.0.19" }, { "status": "affected", "version": "20.4.2.2.1" }, { "status": "affected", "version": "20.5.1.2" }, { "status": "affected", "version": "20.3.4.2" }, { "status": "affected", "version": "20.3.814" }, { "status": "affected", "version": "20.4.2.2" }, { "status": "affected", "version": "20.6.2.2" }, { "status": "affected", "version": "20.3.4.2.1" }, { "status": "affected", "version": "20.7.1.1" }, { "status": "affected", "version": "20.3.4.1.2" }, { "status": "affected", "version": "20.6.2.2.2" }, { "status": "affected", "version": "20.3.4.0.20" }, { "status": "affected", "version": "20.6.2.2.3" }, { "status": "affected", "version": "20.4.2.2.2" }, { "status": "affected", "version": "20.3.5" }, { "status": "affected", "version": "20.6.2.0.4" }, { "status": "affected", "version": "20.4.2.2.3" }, { "status": "affected", "version": "20.3.4.0.24" }, { "status": "affected", "version": "20.6.2.2.7" }, { "status": "affected", "version": "20.6.3" }, { "status": "affected", "version": "20.3.4.2.2" }, { "status": "affected", "version": "20.4.2.2.4" }, { "status": "affected", "version": "20.7.1.0.2" }, { "status": "affected", "version": "20.8.1" }, { "status": "affected", "version": "20.3.5.0.8" }, { "status": "affected", "version": "20.3.5.0.9" }, { "status": "affected", "version": "20.4.2.2.8" }, { "status": "affected", "version": "20.3.5.0.7" }, { "status": "affected", "version": "20.6.3.0.7" }, { "status": "affected", "version": "20.6.3.0.5" }, { "status": "affected", "version": "20.6.3.0.10" }, { "status": "affected", "version": "20.6.3.0.2" }, { "status": "affected", "version": "20.7.2" }, { "status": "affected", "version": "20.9.1EFT2" }, { "status": "affected", "version": "20.6.3.0.11" }, { "status": "affected", "version": "20.6.3.1" }, { "status": "affected", "version": "20.6.3.0.14" }, { "status": "affected", "version": "20.6.4" }, { "status": "affected", "version": "20.9.1" }, { "status": "affected", "version": "20.6.3.0.19" }, { "status": "affected", "version": "20.6.3.0.18" }, { "status": "affected", "version": "20.3.6" }, { "status": "affected", "version": "20.9.1.1" }, { "status": "affected", "version": "20.6.3.0.23" }, { "status": "affected", "version": "20.6.4.0.4" }, { "status": "affected", "version": "20.6.3.0.25" }, { "status": "affected", "version": "20.6.5" }, { "status": "affected", "version": "20.6.3.0.27" }, { "status": "affected", "version": "20.9.2" }, { "status": "affected", "version": "20.9.2.1" }, { "status": "affected", "version": "20.6.3.0.29" }, { "status": "affected", "version": "20.6.3.0.31" }, { "status": "affected", "version": "20.6.3.0.32" }, { "status": "affected", "version": "20.10.1" }, { "status": "affected", "version": "20.6.3.0.33" }, { "status": "affected", "version": "20.9.2.0.01" }, { "status": "affected", "version": "20.9.1_LI_Images" }, { "status": "affected", "version": "20.10.1_LI_Images" }, { "status": "affected", "version": "20.9.2_LI_Images" }, { "status": "affected", "version": "20.3.7" }, { "status": "affected", "version": "20.9.3" }, { "status": "affected", "version": "20.6.5.1" }, { "status": "affected", "version": "20.11.1" }, { "status": "affected", "version": "20.11.1_LI_Images" }, { "status": "affected", "version": "20.9.3_LI_ Images" }, { "status": "affected", "version": "20.6.3.1.1" }, { "status": "affected", "version": "20.9.3.0.2" }, { "status": "affected", "version": "20.6.5.1.2" }, { "status": "affected", "version": "20.9.3.0.3" }, { "status": "affected", "version": "20.4.2.3" }, { "status": "affected", "version": "20.6.3.2" }, { "status": "affected", "version": "20.6.4.1" }, { "status": "affected", "version": "20.6.3.0.38" }, { "status": "affected", "version": "20.6.3.0.39" }, { "status": "affected", "version": "20.3.5.1" }, { "status": "affected", "version": "20.3.4.3" }, { "status": "affected", "version": "20.9.3.1" }, { "status": "affected", "version": "20.3.3.2" }, { "status": "affected", "version": "20.6.5.2" }, { "status": "affected", "version": "20.3.7.1" }, { "status": "affected", "version": "20.10.1.1" }, { "status": "affected", "version": "20.6.5.2.1" }, { "status": "affected", "version": "20.3.4.0.25" }, { "status": "affected", "version": "20.6.2.2.4" }, { "status": "affected", "version": "20.6.1.2" }, { "status": "affected", "version": "20.11.1.1" }, { "status": "affected", "version": "20.9.3.0.5" }, { "status": "affected", "version": "20.3.4.0.26" }, { "status": "affected", "version": "20.6.5.1.3" }, { "status": "affected", "version": "20.6.3.0.40" }, { "status": "affected", "version": "20.1.3.1" }, { "status": "affected", "version": "20.9.2.2" }, { "status": "affected", "version": "20.6.5.2.3" }, { "status": "affected", "version": "20.6.5.1.4" }, { "status": "affected", "version": "20.6.5.3" }, { "status": "affected", "version": "20.6.3.0.41" }, { "status": "affected", "version": "20.9.3.0.7" }, { "status": "affected", "version": "20.6.5.1.5" }, { "status": "affected", "version": "20.9.3.0.4" }, { "status": "affected", "version": "20.6.4.0.19" }, { "status": "affected", "version": "20.6.5.1.6" }, { "status": "affected", "version": "20.9.3.0.8" }, { "status": "affected", "version": "20.6.3.3" }, { "status": "affected", "version": "20.3.7.2" }, { "status": "affected", "version": "20.6.5.4" }, { "status": "affected", "version": "20.6.5.1.7" }, { "status": "affected", "version": "20.9.3.0.12" }, { "status": "affected", "version": "20.6.4.2" }, { "status": "affected", "version": "20.6.5.5" }, { "status": "affected", "version": "20.9.3.2" }, { "status": "affected", "version": "20.11.1.2" }, { "status": "affected", "version": "20.6.3.4" }, { "status": "affected", "version": "20.10.1.2" }, { "status": "affected", "version": "20.6.5.1.9" }, { "status": "affected", "version": "20.9.3.0.16" }, { "status": "affected", "version": "20.6.3.0.45" }, { "status": "affected", "version": "20.6.5.1.10" }, { "status": "affected", "version": "20.9.3.0.17" }, { "status": "affected", "version": "20.6.5.2.4" }, { "status": "affected", "version": "20.6.4.0.21" }, { "status": "affected", "version": "20.9.3.0.18" }, { "status": "affected", "version": "20.6.3.0.46" }, { "status": "affected", "version": "20.6.3.0.47" }, { "status": "affected", "version": "20.9.2.3" }, { "status": "affected", "version": "20.9.3.2_LI_Images" }, { "status": "affected", "version": "20.9.3.0.21" }, { "status": "affected", "version": "20.9.3.0.20" }, { "status": "affected", "version": "20.9.4_LI_Images" }, { "status": "affected", "version": "20.9.4" }, { "status": "affected", "version": "20.6.5.1.11" }, { "status": "affected", "version": "20.12.1" }, { "status": "affected", "version": "20.12.1_LI_Images" }, { "status": "affected", "version": "20.6.5.1.13" }, { "status": "affected", "version": "20.9.3.0.23" }, { "status": "affected", "version": "20.6.5.2.8" }, { "status": "affected", "version": "20.9.4.1" }, { "status": "affected", "version": "20.9.4.1_LI_Images" }, { "status": "affected", "version": "20.9.3.0.25" }, { "status": "affected", "version": "20.9.3.0.24" }, { "status": "affected", "version": "20.6.5.1.14" }, { "status": "affected", "version": "20.3.8" }, { "status": "affected", "version": "20.6.6" }, { "status": "affected", "version": "20.9.3.0.26" }, { "status": "affected", "version": "20.6.3.0.51" }, { "status": "affected", "version": "20.9.3.0.29" }, { "status": "affected", "version": "20.12.2" }, { "status": "affected", "version": "20.12.2_LI_Images" }, { "status": "affected", "version": "20.6.6.0.1" }, { "status": "affected", "version": "20.13.1_LI_Images" }, { "status": "affected", "version": "20.9.4.0.4" }, { "status": "affected", "version": "20.13.1" }, { "status": "affected", "version": "20.9.4.1.1" }, { "status": "affected", "version": "20.9.5" }, { "status": "affected", "version": "20.9.5_LI_Images" }, { "status": "affected", "version": "20.12.3_LI_Images" }, { "status": "affected", "version": "20.12.3" }, { "status": "affected", "version": "20.9.4.1.3" }, { "status": "affected", "version": "20.6.7" }, { "status": "affected", "version": "20.9.5.1" }, { "status": "affected", "version": "20.9.5.1_LI_Images" }, { "status": "affected", "version": "20.9.4.1.6" }, { "status": "affected", "version": "20.14.1" }, { "status": "affected", "version": "20.14.1_LI_Images" }, { "status": "affected", "version": "20.9.5.2" }, { "status": "affected", "version": "20.9.5.2.1" }, { "status": "affected", "version": "20.9.5.2_LI_Images" }, { "status": "affected", "version": "20.12.3.1" }, { "status": "affected", "version": "20.12.4" }, { "status": "affected", "version": "20.15.1_LI_Images" }, { "status": "affected", "version": "20.15.1" }, { "status": "affected", "version": "20.9.5.1.4" }, { "status": "affected", "version": "20.9.5.2.7" }, { "status": "affected", "version": "20.9.5.2.13" }, { "status": "affected", "version": "20.9.6" }, { "status": "affected", "version": "20.9.6_LI_Images" }, { "status": "affected", "version": "20.9.5.2.14" }, { "status": "affected", "version": "20.6.8" }, { "status": "affected", "version": "20.12.4.0.03" }, { "status": "affected", "version": "20.12.4_LI_Images" }, { "status": "affected", "version": "20.9.5.2.16" }, { "status": "affected", "version": "20.12.4.0.4" }, { "status": "affected", "version": "20.12.401" }, { "status": "affected", "version": "20.9.5.3" }, { "status": "affected", "version": "20.9.5.3_LI_Images" }, { "status": "affected", "version": "20.12.4.1_LI_Images" }, { "status": "affected", "version": "20.12.4.1" }, { "status": "affected", "version": "20.9.5.2.21" }, { "status": "affected", "version": "20.9.6.0.3" }, { "status": "affected", "version": "20.12.4.0.6" } ] } ], "descriptions": [ { "lang": "en", "value": "A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, local attacker to gain privileges of the root user on the underlying operating system.\r\n\r\nThis vulnerability is due to insufficient input validation. An authenticated attacker with read-only privileges on the SD-WAN Manager system could exploit this vulnerability by sending a crafted request to the CLI of the SD-WAN Manager. A successful exploit could allow the attacker to gain root privileges on the underlying operating system." } ], "exploits": [ { "lang": "en", "value": "The Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory." } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "cvssV3_1" } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-300", "description": "Channel Accessible by Non-Endpoint", "lang": "en", "type": "cwe" } ] } ], "providerMetadata": { "dateUpdated": "2025-05-07T17:18:27.333Z", "orgId": "d1c1063e-7a18-46af-9102-31f8928bc633", "shortName": "cisco" }, "references": [ { "name": "cisco-sa-sdwan-priviesc-WCk7bmmt", "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-priviesc-WCk7bmmt" } ], "source": { "advisory": "cisco-sa-sdwan-priviesc-WCk7bmmt", "defects": [ "CSCwk92200" ], "discovery": "INTERNAL" }, "title": "Cisco Catalyst SD-WAN Manager Privilege Escalation Vulnerability" } }, "cveMetadata": { "assignerOrgId": "d1c1063e-7a18-46af-9102-31f8928bc633", "assignerShortName": "cisco", "cveId": "CVE-2025-20122", "datePublished": "2025-05-07T17:18:27.333Z", "dateReserved": "2024-10-10T19:15:13.211Z", "dateUpdated": "2025-05-08T03:56:28.948Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1", "meta": { "nvd": "{\"cve\":{\"id\":\"CVE-2025-20122\",\"sourceIdentifier\":\"psirt@cisco.com\",\"published\":\"2025-05-07T18:15:36.290\",\"lastModified\":\"2025-05-08T14:39:09.683\",\"vulnStatus\":\"Awaiting Analysis\",\"cveTags\":[],\"descriptions\":[{\"lang\":\"en\",\"value\":\"A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, local attacker to gain privileges of the root user on the underlying operating system.\\r\\n\\r\\nThis vulnerability is due to insufficient input validation. An authenticated attacker with read-only privileges on the SD-WAN Manager system could exploit this vulnerability by sending a crafted request to the CLI of the SD-WAN Manager. A successful exploit could allow the attacker to gain root privileges on the underlying operating system.\"},{\"lang\":\"es\",\"value\":\"Una vulnerabilidad en la CLI de Cisco Catalyst SD-WAN Manager, anteriormente Cisco SD-WAN vManage, podr\u00eda permitir que un atacante local autenticado obtenga privilegios de usuario root en el sistema operativo subyacente. Esta vulnerabilidad se debe a una validaci\u00f3n de entrada insuficiente. Un atacante autenticado con privilegios de solo lectura en el sistema SD-WAN Manager podr\u00eda explotar esta vulnerabilidad enviando una solicitud manipulada a la CLI de SD-WAN Manager. Una explotaci\u00f3n exitosa podr\u00eda permitir al atacante obtener privilegios root en el sistema operativo subyacente.\"}],\"metrics\":{\"cvssMetricV31\":[{\"source\":\"psirt@cisco.com\",\"type\":\"Primary\",\"cvssData\":{\"version\":\"3.1\",\"vectorString\":\"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\",\"baseScore\":7.8,\"baseSeverity\":\"HIGH\",\"attackVector\":\"LOCAL\",\"attackComplexity\":\"LOW\",\"privilegesRequired\":\"LOW\",\"userInteraction\":\"NONE\",\"scope\":\"UNCHANGED\",\"confidentialityImpact\":\"HIGH\",\"integrityImpact\":\"HIGH\",\"availabilityImpact\":\"HIGH\"},\"exploitabilityScore\":1.8,\"impactScore\":5.9}]},\"weaknesses\":[{\"source\":\"psirt@cisco.com\",\"type\":\"Primary\",\"description\":[{\"lang\":\"en\",\"value\":\"CWE-300\"}]}],\"references\":[{\"url\":\"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-priviesc-WCk7bmmt\",\"source\":\"psirt@cisco.com\"}]}}" } }
Loading...
Loading...
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.