Privilege Escalation Vulnerability in Cisco Industrial Ethernet Switch Device Manager
CVE-2025-20164

8.3HIGH

Key Information:

Vendor
Cisco
Status
Vendor
CVE Published:
7 May 2025

Badges

👾 Exploit Exists

Summary

A security vulnerability exists in the Cisco Industrial Ethernet Switch Device Manager within Cisco IOS Software, enabling an authenticated remote attacker to elevate their privileges. This flaw arises from inadequate authorization validation for users. By crafting a specially designed HTTP request, an attacker with valid credentials can exploit this vulnerability, potentially gaining elevated privileges to the highest level (privilege level 15). Users with read-only access are assigned privilege level 5, highlighting the importance of secure credential management and robust authorization checks in preventing exploitation.

Affected Version(s)

IOS 15.0(2)SE8

IOS 15.0(2)EA

IOS 15.0(2)EA1

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20164 : Privilege Escalation Vulnerability in Cisco Industrial Ethernet Switch Device Manager | SecurityVulnerability.io