CVE-2025-20178 Details
Description
A vulnerability in the web-based management interface of Cisco Secure Network Analytics could allow an authenticated, remote attacker with valid administrative credentials to execute arbitrary commands as root on the underlying operating system. This vulnerability is due to insufficient integrity checks within device backup files. An attacker with valid administrative credentials could exploit this vulnerability by crafting a malicious backup file and restoring it to an affected device. A successful exploit could allow the attacker to obtain shell access on the underlying operating system with the privileges of root.
A vulnerability exists in the web-based management interface of Cisco Secure Network Analytics. It allows an authenticated, remote attacker with valid administrative credentials to execute arbitrary commands as root on the underlying operating system. This issue arises from inadequate integrity checks in device backup files. An attacker could exploit this vulnerability by creating a malicious backup file and restoring it on an affected device, potentially gaining shell access with root privileges.
Cisco has released software updates to address this vulnerability. Users should consult the Cisco Security Advisories page for guidance on upgrading. For specific release information, refer to the Fixed Software section of the advisory.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 17, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sna-prvesc-4BQmK33Z | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-347 | Improper Verification of Cryptographic Signature | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco secure network analytics | 7.5.0 - 7.5.0 rollup_2024-02-22 7.5.0 rollup_2024-03-08 7.5.0 rollup_2024-04-15 7.5.0 rollup_2024-05-15 7.5.0 rollup_2024-06-10 7.5.0 rollup_2024-07-09 7.5.0 rollup_2024-08-13 7.5.0 rollup_2024-09-12 7.5.0 rollup_2024-10-15 7.5.0 rollup_2024-12-02 7.5.0 rollup_2025-01-24 7.5.1 - 7.5.1 rollup_2024-08-14 7.5.1 rollup_2024-09-18 7.5.1 rollup_2024-10-15 7.5.1 rollup_2024-11-12 7.5.1 rollup_2025-01-07 7.5.2 - |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 1, 2025 | Initial Analysis | [email protected] |
| Apr 16, 2025 | New CVE Received | [email protected] |