CVE-2025-20126 Details
Description
A vulnerability in certification validation routines of Cisco ThousandEyes Endpoint Agent for macOS and RoomOS could allow an unauthenticated, remote attacker to intercept or manipulate metrics information. This vulnerability exists because the affected software does not properly validate certificates for hosted metrics services. An on-path attacker could exploit this vulnerability by intercepting network traffic using a crafted certificate. A successful exploit could allow the attacker to masquerade as a trusted host and monitor or change communications between the remote metrics service and the vulnerable client.
A vulnerability exists in the certification validation routines of Cisco ThousandEyes Endpoint Agent for macOS and RoomOS. This issue could allow an unauthenticated, remote attacker to intercept or manipulate metrics information. The vulnerability arises because the software fails to properly validate certificates for hosted metrics services. An on-path attacker could exploit this by intercepting network traffic with a crafted certificate, potentially allowing them to impersonate a trusted host and alter communications between the metrics service and the client.
Cisco has released updates for this vulnerability. The first fixed release for macOS is version 1.206.3, and for RoomOS, it is version 1.207.21. Administrators may also disable the agent instant test feature as a temporary measure, but should evaluate the impact of this workaround on their network.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 8, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-thousandeyes-cert-pqtJUv9N | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-295 | Improper Certificate Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco thousandeyes endpoint agent | < 1.206.3 < 1.207.2 |
CPE
Remediation
| |
| apple macos | All versions |
CPE
Remediation
| |
| cisco roomos | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 22, 2025 | Initial Analysis | [email protected] |
| Jan 8, 2025 | CVE Modified | [email protected] |
| Jan 8, 2025 | New CVE Received | [email protected] |