Data Modification Vulnerability in Cisco Catalyst Center by Cisco
CVE-2025-20223
4.7MEDIUM
Summary
A vulnerability in Cisco Catalyst Center, formerly known as Cisco DNA Center, allows authenticated remote attackers to potentially exploit insufficient access control enforcement on HTTP requests. By crafting specific HTTP requests, an attacker can manipulate data within an affected device's internal services, granting them unauthorized access to sensitive information. This security flaw poses a significant risk to data integrity and privacy for organizations utilizing affected versions of the product.
Affected Version(s)
Cisco Digital Network Architecture Center (DNA Center)
References
CVSS V3.1
Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved