CVE-2025-20341
published 2025-11-13CVE-2025-20341: A vulnerability in Cisco Catalyst Center Virtual Appliance could allow an authenticated, remote attacker to elevate privileges to Administrator on an affected…
PriorityP264high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.51%
40.0th percentile
A vulnerability in Cisco Catalyst Center Virtual Appliance could allow an authenticated, remote attacker to elevate privileges to Administrator on an affected system.
This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted HTTP request to an affected system. A successful exploit could allow the attacker to perform unauthorized modifications to the system, including creating new user accounts or elevating their own privileges on an affected system. To exploit this vulnerability, the attacker must have valid credentials for a user account with at least the role of Observer.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | catalyst_center_virtual_appliance | — | — |
| cisco | cisco_digital_network_architecture_center | — | — |
| cisco | cisco_digital_network_architecture_center | — | — |
| cisco | cisco_digital_network_architecture_center | — | — |
| cisco | cisco_digital_network_architecture_center | — | — |
| cisco | cisco_digital_network_architecture_center | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit vector is a crafted HTTP request submitted by an authenticated user with at least the Observer role targeting Cisco Catalyst Center Virtual Appliance; monitor for unexpected privilege escalation or new account creation originating from low-privileged accounts. ↗
- ·Vulnerability is specific to the Virtual Appliance form factor of Cisco Catalyst Center; confirm deployment type before applying detection logic. ↗
- ·No workarounds exist; the only remediation is applying Cisco's released software updates. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_cisco8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Catalyst Center Virtual Appliance Privilege Escalation Vulnerability
vendor_cisco·2025-11-13·CVSS 8.8
CVE-2025-20341 [HIGH] CWE-284 Cisco Catalyst Center Virtual Appliance Privilege Escalation Vulnerability
Cisco Catalyst Center Virtual Appliance Privilege Escalation Vulnerability
A vulnerability in Cisco Catalyst Center Virtual Appliance could allow an authenticated, remote attacker to elevate privileges to Administrator on an affected system.
This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted HTTP request to an affected system. A successful exploit could allow the attacker to perform unauthorized modifications to the system, including creating new user accounts or elevating their own privileges on an affected system. To exploit this vulnerability, the attacker must have valid credentials for a user account with at least the role of Observer.
Cisco has released software updates that address this
Cisco
Cisco Catalyst Center Virtual Appliance Privilege Escalation Vulnerability
vendor_cisco·CVSS 3.1
CVE-2025-20341 Cisco Catalyst Center Virtual Appliance Privilege Escalation Vulnerability
CVE-2025-20341: Cisco Catalyst Center Virtual Appliance Privilege Escalation Vulnerability
A vulnerability in Cisco Catalyst Center Virtual Appliance could allow an authenticated, remote attacker to elevate privileges to Administrator on an affected system. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted HTTP request to an affected system. A successful exploit could allow the attacker to perform unauthorized modifications to the system, including creating new user accounts or elevating their own privileges on an affected system. To exploit this vulnerability, the attacker must have valid credentials for a user account with at least the role of Observer . Cisco has released software updates tha
GHSA
GHSA-8m7g-q5hf-chf5: A vulnerability in Cisco Catalyst Center Virtual Appliance could allow an authenticated, remote attacker to elevate privileges to Administrator on an
ghsa_unreviewed·2025-11-13
CVE-2025-20341 [HIGH] CWE-284 GHSA-8m7g-q5hf-chf5: A vulnerability in Cisco Catalyst Center Virtual Appliance could allow an authenticated, remote attacker to elevate privileges to Administrator on an
A vulnerability in Cisco Catalyst Center Virtual Appliance could allow an authenticated, remote attacker to elevate privileges to Administrator on an affected system.
This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted HTTP request to an affected system. A successful exploit could allow the attacker to perform unauthorized modifications to the system, including creating new user accounts or elevating their own privileges on an affected system. To exploit this vulnerability, the attacker must have valid credentials for a user account with at least the role of Observer.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-11-13
Published