CVE-2025-20187 Details
Description
A vulnerability in the application data endpoints of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, remote attacker to write arbitrary files to an affected system. This vulnerability is due to improper validation of requests to APIs. An attacker could exploit this vulnerability by sending malicious requests to an API within the affected system. A successful exploit could allow the attacker to conduct directory traversal attacks and write files to an arbitrary location on the affected system.
A vulnerability exists in the application data endpoints of Cisco Catalyst SD-WAN Manager (formerly Cisco SD-WAN vManage), allowing authenticated, remote attackers to write arbitrary files to the system. This issue arises from inadequate validation of requests to APIs, enabling attackers to send malicious requests that could exploit directory traversal vulnerabilities and write files to arbitrary locations on the affected system.
Cisco has released software updates to address this vulnerability. Customers should consult the Cisco Security Advisories page for guidance on upgrading to a fixed release.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 7, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwanarbfile-2zKhKZwJ | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco catalyst sd-wan manager | 17.2.4 17.2.5 17.2.6 17.2.7 17.2.8 17.2.9 17.2.10 18.2.0 18.3.0 18.3.1 18.3.1.1 18.3.3 18.3.3.1 18.3.4 18.3.5 18.3.6 18.3.6.1 18.3.7 18.3.8 18.4.0 18.4.0.1 18.4.1 18.4.3 18.4.4 18.4.5 18.4.6 18.4.302 18.4.303 18.4.501_es 19.0.0 19.0.1a 19.1.0 19.2.0 19.2.1 19.2.2 19.2.3 19.2.4 19.2.4.0.1 19.2.4.0.8 19.2.4.0.9 19.2.31 19.2.32 19.2.097 19.2.098 19.2.099 19.2.929 19.3.0 20.1.1 20.1.1.1 20.1.2 20.1.2_937 20.1.3 20.1.3.1 20.1.12 20.3.1 20.3.2 20.3.2.0.5 20.3.2.0.6 20.3.2.1 20.3.2.1_927 20.3.2.1_930 20.3.2_925 20.3.2_928 20.3.2_929 20.3.2_937 20.3.3 20.3.3.0.8 20.3.3.0.14 20.3.3.0.16 20.3.3.0.17 20.3.3.0.18 20.3.3.1 20.3.3.1.1 20.3.3.1.2 20.3.3.1.5 20.3.3.1.7 20.3.3.1.10 20.3.3.2 20.3.4 20.3.4.0.1 20.3.4.0.5 20.3.4.0.6 20.3.4.0.11 20.3.4.0.19 20.3.4.0.20 20.3.4.0.24 20.3.4.0.25 20.3.4.0.26 20.10.1 20.10.1.1 20.10.1.2 20.11.1 20.11.1.1 20.11.1.2 20.12.1 20.12.2 20.12.3 20.12.3.1 20.12.4 20.12.4.0.03 20.12.4.0.4 20.12.4.1 20.12.401 20.13.1 20.14.1 20.15.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 4, 2025 | Initial Analysis | [email protected] |
| May 7, 2025 | New CVE Received | [email protected] |