CVE-2025-20157 Details
Description
A vulnerability in certificate validation processing of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an unauthenticated, remote attacker to gain access to sensitive information. This vulnerability is due to improper validation of certificates that are used by the Smart Licensing feature. An attacker with a privileged network position could exploit this vulnerability by intercepting traffic that is sent over the Internet. A successful exploit could allow the attacker to gain access to sensitive information, including credentials used by the device to connect to Cisco cloud services.
A vulnerability exists in the certificate validation process of Cisco Catalyst SD-WAN Manager (formerly Cisco SD-WAN vManage). This issue could enable an unauthenticated, remote attacker to access sensitive information. The vulnerability arises from improper validation of certificates used by the Smart Licensing feature. An attacker with a privileged network position could exploit this by intercepting Internet traffic, potentially gaining access to sensitive data, including credentials used by the device to connect to Cisco cloud services.
Cisco has released software updates to address this vulnerability. Customers are advised to upgrade to a fixed release. For guidance on upgrading, consult the Cisco Security Advisories page or contact the Cisco Technical Assistance Center (TAC) or a contracted maintenance provider.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 7, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-catalyst-tls-PqnD5KEJ | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-295 | Improper Certificate Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco catalyst sd-wan manager | 17.2.4 17.2.5 17.2.6 17.2.7 17.2.8 17.2.9 17.2.10 18.2.0 18.3.0 18.3.1 18.3.1.1 18.3.3 18.3.3.1 18.3.4 18.3.5 18.3.6 18.3.6.1 18.3.7 18.3.8 18.4.0 18.4.0.1 18.4.1 18.4.3 18.4.4 18.4.5 18.4.6 18.4.302 18.4.303 18.4.501_es 19.0.0 19.0.1a 19.1.0 19.2.0 19.2.1 19.2.2 19.2.3 19.2.4 19.2.4.0.1 19.2.4.0.8 19.2.4.0.9 19.2.31 19.2.32 19.2.097 19.2.098 19.2.099 19.2.929 19.3.0 20.1.1 20.1.1.1 20.1.2 20.1.2_937 20.1.3 20.1.3.1 20.1.12 20.3.1 20.3.2 20.3.2.0.5 20.3.2.0.6 20.3.2.1 20.3.2.1_927 20.3.2.1_930 20.3.2_925 20.3.2_928 20.3.2_929 20.3.2_937 20.3.3 20.3.3.0.2 20.3.3.0.4 20.3.3.0.8 20.3.3.0.14 20.3.3.0.16 20.3.3.0.17 20.3.3.0.18 20.3.3.1 20.3.3.1.1 20.3.3.1.2 20.3.3.1.5 20.3.3.1.7 20.3.3.1.10 20.3.3.2 20.3.4 20.3.4.0.1 20.3.4.0.5 20.3.4.0.6 20.3.4.0.9 20.3.4.0.11 20.3.4.0.19 20.3.4.0.20 20.3.4.0.24 20.3.4.0.25 20.3.4.0.26 20.3.4.1 20.3.4.1.1 20.3.4.1.2 20.3.4.2 20.3.4.2.1 20.3.4.2.2 20.3.4.3 20.3.5 20.3.5.0.7 20.3.5.0.8 20.3.5.0.9 20.3.5.1 20.3.6 20.3.7 20.3.7.1 20.3.7.2 20.3.8 20.3.813 20.3.814 20.4.1 20.4.1.0.01 20.4.1.0.1 20.4.1.0.02 20.4.1.1 20.4.1.1.5 20.4.1.2 20.4.2 20.4.2.0.1 20.4.2.0.2 20.4.2.0.4 20.4.2.1 20.4.2.1.1 20.4.2.2 20.4.2.2.1 20.4.2.2.2 20.4.2.2.3 20.4.2.2.4 20.4.2.2.8 20.4.2.3 20.5.0.1.1 20.5.1 20.5.1.0.1 20.5.1.0.2 20.5.1.1 20.5.1.2 20.6.0.18.3 20.6.0.18.4 20.6.1 20.6.1.0.1 20.6.1.1 20.6.1.2 20.6.2 20.6.2.0.4 20.6.2.1 20.6.2.2 20.6.2.2.2 20.6.2.2.3 20.6.2.2.4 20.6.2.2.7 20.6.3 20.6.3.0.2 20.6.3.0.5 20.6.3.0.7 20.6.3.0.10 20.6.3.0.11 20.6.3.0.14 20.6.3.0.18 20.6.3.0.19 20.6.3.0.23 20.6.3.0.25 20.6.3.0.27 20.6.3.0.29 20.6.3.0.31 20.6.3.0.32 20.6.3.0.33 20.6.3.0.38 20.6.3.0.39 20.6.3.0.40 20.6.3.0.41 20.6.3.0.45 20.6.3.0.46 20.6.3.0.47 20.6.3.0.51 20.6.3.1 20.6.3.1.1 20.6.3.2 20.6.3.3 20.6.3.4 20.6.4 20.6.4.0.4 20.6.4.0.19 20.6.4.0.21 20.6.4.1 20.6.4.2 20.6.5 20.6.5.1 20.6.5.1.2 20.6.5.1.3 20.6.5.1.4 20.6.5.1.5 20.6.5.1.6 20.6.5.1.7 20.6.5.1.9 20.6.5.1.10 20.6.5.1.11 20.6.5.1.13 20.6.5.1.14 20.6.5.2 20.6.5.2.1 20.6.5.2.3 20.6.5.2.4 20.6.5.2.8 20.6.5.3 20.6.5.4 20.6.5.5 20.6.6 20.6.6.0.1 20.6.7 20.6.8 20.7.1 20.7.1.0.2 20.7.1.1 20.7.1eft2 20.7.2 20.8.1 20.9.1 20.9.1.1 20.9.1eft2 20.9.2 20.9.2.0.01 20.9.2.1 20.9.2.2 20.9.2.3 20.9.3 20.9.3.0.2 20.9.3.0.3 20.9.3.0.4 20.9.3.0.5 20.9.3.0.7 20.9.3.0.8 20.9.3.0.12 20.9.3.0.16 20.9.3.0.17 20.9.3.0.18 20.9.3.0.20 20.9.3.0.21 20.9.3.0.23 20.9.3.0.24 20.9.3.0.25 20.9.3.0.26 20.9.3.0.29 20.9.3.1 20.9.3.2 20.9.4 20.9.4.0.4 20.9.4.1 20.9.4.1.1 20.9.4.1.3 20.9.4.1.6 20.9.5 20.9.5.1 20.9.5.1.4 20.9.5.2 20.9.5.2.1 20.9.5.2.7 20.9.5.2.13 20.9.5.2.14 20.9.5.2.16 20.9.5.2.21 20.9.5.3 20.9.6 20.10.1 20.10.1.1 20.10.1.2 20.11.1 20.11.1.1 20.11.1.2 20.12.1 20.12.2 20.12.3 20.12.3.1 20.12.4 20.12.4.0.03 20.12.4.0.4 20.12.4.1 20.12.4_monthly_es5 20.12.401 20.13.1 20.14.1 20.15.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 4, 2025 | Initial Analysis | [email protected] |
| May 7, 2025 | New CVE Received | [email protected] |