Certification Validation Flaw in Cisco ThousandEyes Endpoint Agent for macOS and RoomOS
CVE-2025-20126
Currently unrated
Summary
A security issue exists within the certification validation routines of Cisco's ThousandEyes Endpoint Agent for macOS and RoomOS. This flaw permits an unauthenticated, remote attacker to potentially intercept or manipulate metrics data by exploiting the lack of proper certificate validation for hosted metrics services. An attacker could compromise network traffic with a maliciously crafted certificate, leading to unauthorized access and manipulation of communications between the vulnerable client and the trusted metrics service.
References
Timeline
Vulnerability published