#VU112139 OS Command Injection in Cisco DNA Spaces Connector - CVE-2025-20308
Published: July 3, 2025
Cisco DNA Spaces Connector
Cisco Systems, Inc
Description
The vulnerability allows a local user to execute arbitrary shell commands on the target system.
The vulnerability exists due to insufficient restrictions during the execution of specific CLI commands. A local administrator can execute arbitrary OS commands on the target system with elevated privileges.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.