CVE-2025-20117 Details
Description
A vulnerability in the CLI of Cisco APIC could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient validation of arguments that are passed to specific CLI commands. An attacker could exploit this vulnerability by including crafted input as the argument of an affected CLI command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of root.
A command injection vulnerability has been identified in the Command Line Interface (CLI) of Cisco Application Policy Infrastructure Controller (APIC). This vulnerability allows an authenticated, local attacker to execute arbitrary commands as root on the underlying operating system of the affected device. The issue arises from insufficient validation of arguments passed to specific CLI commands, enabling attackers to exploit it by injecting crafted input. Successful exploitation could lead to unauthorized command execution with root privileges.
Cisco has released software updates to address this vulnerability. For Cisco APIC versions 5.3 and earlier, users should migrate to a fixed release. For version 6.0, the first fixed release is 6.0(8e), and for version 6.1, it is 6.1(2f).
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 26, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apic-multi-vulns-9ummtg5 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco application policy infrastructure controller | 3.2(1l) 3.2(1m) 3.2(2l) 3.2(2o) 3.2(3i) 3.2(3j) 3.2(3n) 3.2(3o) 3.2(3r) 3.2(3s) 3.2(4d) 3.2(4e) 3.2(5d) 3.2(5e) 3.2(5f) 3.2(6i) 3.2(7f) 3.2(7k) 3.2(8d) 3.2(9b) 3.2(9f) 3.2(9h) 3.2(10e) 3.2(10f) 3.2(10g) 3.2(41d) 4.0(1h) 4.0(2c) 4.0(3c) 4.0(3d) 4.1(1a) 4.1(1i) 4.1(1j) 4.1(1k) 4.1(1l) 4.1(2g) 4.1(2m) 4.1(2o) 4.1(2s) 4.1(2u) 4.1(2w) 4.1(2x) 4.2(1g) 4.2(1i) 4.2(1j) 4.2(1l) 4.2(2e) 4.2(2f) 4.2(2g) 4.2(3j) 4.2(3l) 4.2(3n) 4.2(3q) 4.2(4i) 4.2(4k) 4.2(4o) 4.2(4p) 4.2(5k) 4.2(5l) 4.2(5n) 4.2(6d) 4.2(6g) 4.2(6h) 4.2(6l) 4.2(6o) 4.2(7f) 4.2(7l) 4.2(7q) 4.2(7r) 4.2(7s) 4.2(7t) 4.2(7u) 4.2(7v) 4.2(7w) 5.0(1k) 5.0(1l) 5.0(2e) 5.0(2h) 5.1(1h) 5.1(2e) 5.1(3e) 5.1(4c) 5.2(1g) 5.2(2e) 5.2(2f) 5.2(2g) 5.2(2h) 5.2(3e) 5.2(3f) 5.2(3g) 5.2(4d) 5.2(4e) 5.2(4f) 5.2(4h) 5.2(5c) 5.2(5d) 5.2(5e) 5.2(6e) 5.2(6g) 5.2(6h) 5.2(7f) 5.2(7g) 5.2(8d) 5.2(8e) 5.2(8f) 5.2(8g) 5.2(8h) 5.2(8i) 5.3(1d) 5.3(2a) 5.3(2b) 5.3(2c) 5.3(2d) 5.3(2e) 6.0(1g) 6.0(1j) 6.0(2h) 6.0(2j) 6.0(3d) 6.0(3e) 6.0(3g) 6.0(4c) 6.0(5h) 6.0(5j) 6.0(6c) 6.0(7e) 6.0(8d) 6.1(1f) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 31, 2025 | Initial Analysis | [email protected] |
| Feb 26, 2025 | New CVE Received | [email protected] |