Remote Command Execution Vulnerability in Cisco Catalyst Center REST API
CVE-2025-20349
6.3MEDIUM
What is CVE-2025-20349?
A vulnerability exists within the REST API of Cisco Catalyst Center, allowing an authenticated remote attacker to execute arbitrary commands with root privileges in a restricted container. This exploit emerges from inadequate validation of user-supplied input in API request parameters. An attacker with valid credentials, possessing at least Observer role access, can leverage this flaw by sending specially crafted API requests, potentially leading to unauthorized command execution that can compromise the integrity of the system.
Affected Version(s)
Cisco Digital Network Architecture Center (DNA Center) 1.4.0.0
Cisco Digital Network Architecture Center (DNA Center) 2.1.1.0
Cisco Digital Network Architecture Center (DNA Center) 2.1.1.3