Certification Validation Flaw in Cisco ThousandEyes Endpoint Agent for macOS and RoomOS
CVE-2025-20126

Currently unrated

Key Information:

Vendor
Cisco
Vendor
CVE Published:
8 January 2025

Summary

A security issue exists within the certification validation routines of Cisco's ThousandEyes Endpoint Agent for macOS and RoomOS. This flaw permits an unauthenticated, remote attacker to potentially intercept or manipulate metrics data by exploiting the lack of proper certificate validation for hosted metrics services. An attacker could compromise network traffic with a maliciously crafted certificate, leading to unauthorized access and manipulation of communications between the vulnerable client and the trusted metrics service.

References

Timeline

  • Vulnerability published

.