Improper access control in Cisco Catalyst Center Virtual Appliance - CVE-2025-20341

 

Improper access control in Cisco Catalyst Center Virtual Appliance - CVE-2025-20341

Published: November 13, 2025


Vulnerability identifier: #VU118524
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-20341
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to escalate privileges on the system.

The vulnerability exists due to improper access restrictions. A remote user can send a specially crafted HTTP request and perform unauthorized modifications to the system, including creating new user accounts or elevating their own privileges on an affected system.


Affected software

Cisco Catalyst Center Virtual Appliance

How to mitigate CVE-2025-20341

Install updates from vendor's website.

Cisco Catalyst Center Virtual Appliance - update to 2.3.7.10-VA

External References

Related Security Bulletins