Open Redirect Vulnerability in Cisco Catalyst Center Virtual Appliance
CVE-2025-20355
What is CVE-2025-20355?
A security flaw exists in the web-based management interface of the Cisco Catalyst Center Virtual Appliance that allows an unprivileged remote attacker to redirect users to a malicious web page. This is caused by improper input validation of HTTP request parameters, enabling attackers to intercept and alter requests. Exploiting this vulnerability could lead users to harmful sites, increasing the risk of phishing attacks and data breaches.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cisco Digital Network Architecture Center (DNA Center) 1.4.0.0
Cisco Digital Network Architecture Center (DNA Center) 2.1.1.0
Cisco Digital Network Architecture Center (DNA Center) 2.1.1.3
References
CVSS V3.1
Timeline
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved