API Management Vulnerability in Cisco Catalyst Center
CVE-2025-20210
Summary
A vulnerability exists in the management API of Cisco Catalyst Center, which may enable unauthenticated attackers to access and alter outgoing proxy configuration settings. This issue arises from insufficient authentication mechanisms within the API endpoint. By exploiting this vulnerability, an attacker can send crafted requests to the API, potentially disrupting internet traffic managed by the Cisco Catalyst Center or allowing interception of outbound traffic. Organizations using this product should take immediate action to secure their systems against potential attacks.
Affected Version(s)
Cisco Digital Network Architecture Center (DNA Center) 2.1.1.0
Cisco Digital Network Architecture Center (DNA Center) 2.1.1.3
Cisco Digital Network Architecture Center (DNA Center) 2.1.2.0
References
CVSS V3.1
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved