CVE-2025-20122 Details
Description
A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, local attacker to gain privileges of the root user on the underlying operating system. This vulnerability is due to insufficient input validation. An authenticated attacker with read-only privileges on the SD-WAN Manager system could exploit this vulnerability by sending a crafted request to the CLI of the SD-WAN Manager. A successful exploit could allow the attacker to gain root privileges on the underlying operating system.
A vulnerability exists in the CLI of Cisco Catalyst SD-WAN Manager that could allow an authenticated, local attacker to gain root privileges on the underlying operating system. This issue arises from inadequate input validation. An authenticated attacker with read-only access could exploit this vulnerability by sending a crafted request to the CLI. Successful exploitation would result in elevated privileges on the operating system.
Cisco has released free software updates to address this vulnerability. Customers with service contracts should obtain these updates through their usual channels. For those without service contracts, contact the Cisco Technical Assistance Center (TAC) for assistance. This vulnerability is part of a collection of vulnerabilities in Cisco Catalyst SD-WAN Manager, and customers are advised to upgrade to a fixed release. Consult the Cisco Security Advisories page for guidance on exposure and upgrade solutions.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 8, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-priviesc-WCk7bmmt | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-300 | Channel Accessible by Non-Endpoint | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco catalyst sd-wan manager | 17.2.4 17.2.5 17.2.6 17.2.7 17.2.8 17.2.9 17.2.10 18.2.0 18.3.0 18.3.1 18.3.1.1 18.3.3 18.3.3.1 18.3.4 18.3.5 18.3.6 18.3.6.1 18.3.7 18.3.8 18.4.0 18.4.0.1 18.4.1 18.4.3 18.4.4 18.4.5 18.4.6 18.4.302 18.4.303 18.4.501_es 19.0.0 19.0.1a 19.1.0 19.2.0 19.2.1 19.2.2 19.2.3 19.2.4 19.2.4.0.1 19.2.4.0.8 19.2.4.0.9 19.2.31 19.2.32 19.2.097 19.2.098 19.2.099 19.2.929 19.3.0 20.1.1 20.1.1.1 20.1.2 20.1.2_937 20.1.3 20.1.3.1 20.1.12 20.3.1 20.3.2 20.3.2.0.5 20.3.2.0.6 20.3.2.1 20.3.2.1_927 20.3.2.1_930 20.3.2_925 20.3.2_928 20.3.2_929 20.3.2_937 20.3.3 20.3.3.0.2 20.3.3.0.4 20.3.3.0.8 20.3.3.0.14 20.3.3.0.16 20.3.3.0.17 20.3.3.0.18 20.3.3.1 20.3.3.1.1 20.3.3.1.2 20.3.3.1.5 20.3.3.1.7 20.3.3.1.10 20.3.3.2 20.3.4 20.3.4.0.1 20.3.4.0.5 20.3.4.0.6 20.3.4.0.9 20.3.4.0.11 20.3.4.0.19 20.3.4.0.20 20.3.4.0.24 20.3.4.0.25 20.3.4.0.26 20.3.4.1 20.3.4.1.1 20.3.4.1.2 20.3.4.2 20.3.4.2.1 20.3.4.2.2 20.3.4.3 20.3.5 20.3.5.0.7 20.3.5.0.8 20.3.5.0.9 20.3.5.1 20.3.6 20.3.7 20.3.7.1 20.3.7.2 20.3.8 20.3.813 20.3.814 20.4.1 20.4.1.0.01 20.4.1.0.1 20.4.1.0.02 20.4.1.1 20.4.1.1.5 20.4.1.2 20.4.2 20.4.2.0.1 20.4.2.0.2 20.4.2.0.4 20.4.2.1 20.4.2.1.1 20.4.2.2 20.4.2.2.1 20.4.2.2.2 20.4.2.2.3 20.4.2.2.4 20.4.2.2.8 20.4.2.3 20.5.0.1.1 20.5.1 20.5.1.0.1 20.5.1.0.2 20.5.1.1 20.5.1.2 20.6.0.18.3 20.6.0.18.4 20.6.1 20.6.1.0.1 20.6.1.1 20.6.1.2 20.6.2 20.6.2.0.4 20.6.2.1 20.6.2.2 20.6.2.2.2 20.6.2.2.3 20.6.2.2.4 20.6.2.2.7 20.6.3 20.6.3.0.2 20.6.3.0.5 20.6.3.0.7 20.6.3.0.10 20.6.3.0.11 20.6.3.0.14 20.6.3.0.18 20.6.3.0.19 20.6.3.0.23 20.6.3.0.25 20.6.3.0.27 20.6.3.0.29 20.6.3.0.31 20.6.3.0.32 20.6.3.0.33 20.6.3.0.38 20.6.3.0.39 20.6.3.0.40 20.6.3.0.41 20.6.3.0.45 20.6.3.0.46 20.6.3.0.47 20.6.3.0.51 20.6.3.1 20.6.3.1.1 20.6.3.2 20.6.3.3 20.6.3.4 20.6.4 20.6.4.0.4 20.6.4.0.19 20.6.4.0.21 20.6.4.1 20.6.4.2 20.6.5 20.6.5.1 20.6.5.1.2 20.6.5.1.3 20.6.5.1.4 20.6.5.1.5 20.6.5.1.6 20.6.5.1.7 20.6.5.1.9 20.6.5.1.10 20.6.5.1.11 20.6.5.1.13 20.6.5.1.14 20.6.5.2 20.6.5.2.1 20.6.5.2.3 20.6.5.2.4 20.6.5.2.8 20.6.5.3 20.6.5.4 20.6.5.5 20.6.6 20.6.6.0.1 20.6.7 20.6.8 20.7.1 20.7.1.0.2 20.7.1.1 20.7.1eft2 20.7.2 20.8.1 20.9.1 20.9.1.1 20.9.1eft2 20.9.2 20.9.2.0.01 20.9.2.1 20.9.2.2 20.9.2.3 20.9.3 20.9.3.0.2 20.9.3.0.3 20.9.3.0.4 20.9.3.0.5 20.9.3.0.7 20.9.3.0.8 20.9.3.0.12 20.9.3.0.16 20.9.3.0.17 20.9.3.0.18 20.9.3.0.20 20.9.3.0.21 20.9.3.0.23 20.9.3.0.24 20.9.3.0.25 20.9.3.0.26 20.9.3.0.29 20.9.3.1 20.9.3.2 20.9.4 20.9.4.0.4 20.9.4.1 20.9.4.1.1 20.9.4.1.3 20.9.4.1.6 20.9.5 20.9.5.1 20.9.5.1.4 20.9.5.2 20.9.5.2.1 20.9.5.2.7 20.9.5.2.13 20.9.5.2.14 20.9.5.2.16 20.9.5.2.21 20.9.5.3 20.9.6 20.9.6.0.3 20.10.1 20.10.1.1 20.10.1.2 20.11.1 20.11.1.1 20.11.1.2 20.12.1 20.12.2 20.12.3 20.12.3.1 20.12.4 20.12.4.0.03 20.12.4.0.4 20.12.4.0.6 20.12.4.1 20.12.401 20.13.1 20.14.1 20.15.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 31, 2025 | Initial Analysis | [email protected] |
| May 7, 2025 | New CVE Received | [email protected] |