CVE-2025-20118
published 2025-02-26CVE-2025-20118: A vulnerability in the implementation of the internal system processes of Cisco APIC could allow an authenticated, local attacker to access sensitive…
PriorityP420medium4.4CVSS 3.1
AVLACLPRHUINSUCHINAN
EPSS
0.15%
4.9th percentile
A vulnerability in the implementation of the internal system processes of Cisco APIC could allow an authenticated, local attacker to access sensitive information on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials.
This vulnerability is due to insufficient masking of sensitive information that is displayed through system CLI commands. An attacker could exploit this vulnerability by using reconnaissance techniques at the device CLI. A successful exploit could allow the attacker to access sensitive information on an affected device that could be used for additional attacks.
Affected
257 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | application_policy_infrastructure_controller | — | — |
| cisco | application_policy_infrastructure_controller | — | — |
| cisco | application_policy_infrastructure_controller | — | — |
| cisco | application_policy_infrastructure_controller | — | — |
| cisco | application_policy_infrastructure_controller | — | — |
| cisco | application_policy_infrastructure_controller | — | — |
| cisco | application_policy_infrastructure_controller | — | — |
| cisco | application_policy_infrastructure_controller | — | — |
| cisco | application_policy_infrastructure_controller | — | — |
| cisco | application_policy_infrastructure_controller | — | — |
| cisco | application_policy_infrastructure_controller | — | — |
| cisco | application_policy_infrastructure_controller | — | — |
| cisco | application_policy_infrastructure_controller | — | — |
| cisco | application_policy_infrastructure_controller | — | — |
| cisco | application_policy_infrastructure_controller | — | — |
| cisco | application_policy_infrastructure_controller | — | — |
| cisco | application_policy_infrastructure_controller | — | — |
| cisco | application_policy_infrastructure_controller | — | — |
| cisco | application_policy_infrastructure_controller | — | — |
| cisco | application_policy_infrastructure_controller | — | — |
| cisco | application_policy_infrastructure_controller | — | — |
| cisco | application_policy_infrastructure_controller | — | — |
| cisco | application_policy_infrastructure_controller | — | — |
| cisco | application_policy_infrastructure_controller | — | — |
| cisco | application_policy_infrastructure_controller | — | — |
CVSS provenance
nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
cisa7.2HIGH
vendor_cisco6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hgqp-f75h-6p8r: A vulnerability in the implementation of the internal system processes of Cisco APIC could allow an authenticated, local attacker to access sensitive
ghsa_unreviewed·2025-02-26
CVE-2025-20118 [MEDIUM] CWE-212 GHSA-hgqp-f75h-6p8r: A vulnerability in the implementation of the internal system processes of Cisco APIC could allow an authenticated, local attacker to access sensitive
A vulnerability in the implementation of the internal system processes of Cisco APIC could allow an authenticated, local attacker to access sensitive information on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials.
This vulnerability is due to insufficient masking of sensitive information that is displayed through system CLI commands. An attacker could exploit this vulnerability by using reconnaissance techniques at the device CLI. A successful exploit could allow the attacker to access sensitive information on an affected device that could be used for additional attacks.
CISA
Cisco Small Business RV Series Routers Command Injection Vulnerability
cisa·2025-03-03·CVSS 7.2
CVE-2023-20118 [MEDIUM] CWE-77 Cisco Small Business RV Series Routers Command Injection Vulnerability
Vulnerability: Cisco Small Business RV Series Routers Command Injection Vulnerability
Affected: Cisco Small Business RV Series Routers
Multiple Cisco Small Business RV Series Routers contains a command injection vulnerability in the web-based management interface. Successful exploitation could allow an authenticated, remote attacker to gain root-level privileges and access unauthorized data.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sbr042-multi-vuln-ej76Pke5 ; https://nvd.nist.gov/vuln/detail/CVE-2023-20118
Remediation Due Date: 2025-03-24
Cisco
Cisco Application Policy Infrastructure Controller Vulnerabilities
vendor_cisco·2025-02-26·CVSS 6.0
CVE-2025-20116 [MEDIUM] CWE-77 Cisco Application Policy Infrastructure Controller Vulnerabilities
Cisco Application Policy Infrastructure Controller Vulnerabilities
Multiple vulnerabilities in Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated attacker to access sensitive information, execute arbitrary commands, cause a denial of service (DoS) condition, or perform cross-site scripting (XSS) attacks. To exploit these vulnerabilities, the attacker must have valid administrative credentials.
For more information about these vulnerabilities, see the Details section of this advisory.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apic-
Cisco
Cisco Application Policy Infrastructure Controller Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2025-20118 [MEDIUM] Cisco Application Policy Infrastructure Controller Vulnerabilities
CVE-2025-20118: Cisco Application Policy Infrastructure Controller Vulnerabilities
Multiple vulnerabilities in Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated attacker to access sensitive information, execute arbitrary commands, cause a denial of service (DoS) condition, or perform cross-site scripting (XSS) attacks. To exploit these vulnerabilities, the attacker must have valid administrative credentials. For more information about these vulnerabilities, see the
Severity: medium
CVSS: 3.1
CWE: CWE-77, CWE-79, CWE-77, CWE-79
Bug IDs: CSCwk18862, CSCwk18863, CSCwk18864, CSCwk18862, CSCwk18863
Suricata
ET WEB_SPECIFIC_APPS Cisco Small Business Router RV Series Command Injection (CVE-2023-20118) M1
suricata·2025-02-27·CVSS 6.5
CVE-2023-20118 [MEDIUM] ET WEB_SPECIFIC_APPS Cisco Small Business Router RV Series Command Injection (CVE-2023-20118) M1
ET WEB_SPECIFIC_APPS Cisco Small Business Router RV Series Command Injection (CVE-2023-20118) M1
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Cisco Small Business Router RV Series Command Injection (CVE-2023-20118) M1"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/cgi-bin/config_mirror.exp|3f|"; fast_pattern; content:"_cert"; distance:0; pcre:"/^[^\s]*?[\x3b\x60\x7c\x24]/R"; reference:url,www.iotsec-zone.com/article/383; reference:cve,2023-20118; classtype:web-application-attack; sid:2060432; rev:1; metadata:attack_target Server, tls_state TLSDecrypt, created_at 2025_02_27, cve CVE_2023_20118, deployment Perimeter, deployment Internal, deployment SSLDecrypt, confidence High, signature_severity Major, tag Exploit, updated_at
Suricata
ET WEB_SPECIFIC_APPS Cisco Small Business Router RV Series Command Injection (CVE-2023-20118) M2
suricata·2025-02-27·CVSS 6.5
CVE-2023-20118 [MEDIUM] ET WEB_SPECIFIC_APPS Cisco Small Business Router RV Series Command Injection (CVE-2023-20118) M2
ET WEB_SPECIFIC_APPS Cisco Small Business Router RV Series Command Injection (CVE-2023-20118) M2
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Cisco Small Business Router RV Series Command Injection (CVE-2023-20118) M2"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/cgi-bin/config.exp|3f|"; fast_pattern; content:"_cert"; distance:0; pcre:"/^[^\s]*?[\x3b\x60\x7c\x24]/R"; reference:url,www.iotsec-zone.com/article/383; reference:cve,2023-20118; classtype:web-application-attack; sid:2060433; rev:1; metadata:affected_product Cisco_RV_Series, attack_target Server, tls_state TLSDecrypt, created_at 2025_02_27, cve CVE_2023_20118, deployment Perimeter, deployment Internal, deployment SSLDecrypt, confidence High, signature_severity Maj
No public exploits indexed.
No writeups or analysis indexed.
2025-02-26
Published