Open Redirect Vulnerability in Cisco Catalyst Center Virtual Appliance
CVE-2025-20355

4.7MEDIUM

Key Information:

Vendor

Cisco

Vendor
CVE Published:
13 November 2025

Badges

👾 Exploit Exists

What is CVE-2025-20355?

A security flaw exists in the web-based management interface of the Cisco Catalyst Center Virtual Appliance that allows an unprivileged remote attacker to redirect users to a malicious web page. This is caused by improper input validation of HTTP request parameters, enabling attackers to intercept and alter requests. Exploiting this vulnerability could lead users to harmful sites, increasing the risk of phishing attacks and data breaches.

Affected Version(s)

Cisco Digital Network Architecture Center (DNA Center) 1.4.0.0

Cisco Digital Network Architecture Center (DNA Center) 2.1.1.0

Cisco Digital Network Architecture Center (DNA Center) 2.1.1.3

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20355 : Open Redirect Vulnerability in Cisco Catalyst Center Virtual Appliance