File Overwrite Vulnerability in Cisco Catalyst SD-WAN Manager
CVE-2025-20213

5.5MEDIUM

Key Information:

Vendor
Cisco
Vendor
CVE Published:
7 May 2025

Badges

👾 Exploit Exists

Summary

A security flaw in the CLI of Cisco Catalyst SD-WAN Manager allows authenticated, local attackers with read-only credentials to overwrite arbitrary files on the device's local file system. This vulnerability arises from improper access controls, enabling attackers to execute crafted commands that compromise file integrity. Successful exploitation provides the attacker with the potential to escalate privileges to the root user, thus posing serious risks to device security and data integrity.

Affected Version(s)

Cisco Catalyst SD-WAN Manager 20.1.12

Cisco Catalyst SD-WAN Manager 19.2.1

Cisco Catalyst SD-WAN Manager 18.4.4

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.