← Back

CVE-2025-20187

nvd nist
Published: May 7, 2025Modified: Aug 4, 2025

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Exploitability: 2.8 / Impact: 3.6
Source: psirt@cisco.com (Secondary)

Description

A vulnerability in the application data endpoints of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, remote attacker to write arbitrary files to an affected system. This vulnerability is due to improper validation of requests to APIs. An attacker could exploit this vulnerability by sending malicious requests to an API within the affected system. A successful exploit could allow the attacker to conduct directory traversal attacks and write files to an arbitrary location on the affected system.

Affected (106)

1 product
Catalyst Sd Wan Manager
Configuration A
106 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 17.2.10
Version 17.2.4
Version 17.2.5
Version 17.2.6
Version 17.2.7
Version 17.2.8
Version 17.2.9
Version 18.2.0
Version 18.3.0
Version 18.3.1.1
Version 18.3.1
Version 18.3.3.1
Version 18.3.3
Version 18.3.4
Version 18.3.5
Version 18.3.6.1
Version 18.3.6
Version 18.3.7
Version 18.3.8
Version 18.4.0.1
Version 18.4.0
Version 18.4.1
Version 18.4.302
Version 18.4.303
Version 18.4.3
Version 18.4.4
Version 18.4.501_es
Version 18.4.5
Version 18.4.6
Version 19.0.0
Version 19.0.1a
Version 19.1.0
Version 19.2.097
Version 19.2.098
Version 19.2.099
Version 19.2.0
Version 19.2.1
Version 19.2.2
Version 19.2.31
Version 19.2.32
Version 19.2.3
Version 19.2.4.0.1
Version 19.2.4.0.8
Version 19.2.4.0.9
Version 19.2.4
Version 19.2.929
Version 19.3.0
Version 20.1.1.1
Version 20.1.12
Version 20.1.1
Version 20.1.2
Version 20.1.2_937
Version 20.1.3.1
Version 20.1.3
Version 20.10.1.1
Version 20.10.1.2
Version 20.10.1
Version 20.11.1.1
Version 20.11.1.2
Version 20.11.1
Version 20.12.1
Version 20.12.2
Version 20.12.3.1
Version 20.12.3
Version 20.12.4.0.03
Version 20.12.4.0.4
Version 20.12.4.1
Version 20.12.401
Version 20.12.4
Version 20.13.1
Version 20.14.1
Version 20.15.1
Version 20.3.1
Version 20.3.2.0.5
Version 20.3.2.0.6
Version 20.3.2.1
Version 20.3.2.1_927
Version 20.3.2.1_930
Version 20.3.2
Version 20.3.2_925
Version 20.3.2_928
Version 20.3.2_929
Version 20.3.2_937
Version 20.3.3.0.14
Version 20.3.3.0.16
Version 20.3.3.0.17
Version 20.3.3.0.18
Version 20.3.3.0.8
Version 20.3.3.1.10
Version 20.3.3.1.1
Version 20.3.3.1.2
Version 20.3.3.1.5
Version 20.3.3.1.7
Version 20.3.3.1
Version 20.3.3.2
Version 20.3.3
Version 20.3.4.0.11
Version 20.3.4.0.19
Version 20.3.4.0.1
Version 20.3.4.0.20
Version 20.3.4.0.24
Version 20.3.4.0.25
Version 20.3.4.0.26
Version 20.3.4.0.5
Version 20.3.4.0.6
Version 20.3.4

Timeline

No history available yet.