CVE-2025-20178

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
16/04/2025
Last modified:
01/08/2025

Description

A vulnerability in the web-based management interface of Cisco Secure Network Analytics could allow an authenticated, remote attacker with valid administrative credentials to execute arbitrary commands as root on the underlying operating system.<br /> <br /> <br /> This vulnerability is due to insufficient integrity checks within device backup files. An attacker with valid administrative credentials could exploit this vulnerability by crafting a malicious backup file and restoring it to an affected device. A successful exploit could allow the attacker to obtain shell access on the underlying operating system with the privileges of root.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cisco:secure_network_analytics:7.5.0:-:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_network_analytics:7.5.0:rollup_2024-02-22:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_network_analytics:7.5.0:rollup_2024-03-08:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_network_analytics:7.5.0:rollup_2024-04-15:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_network_analytics:7.5.0:rollup_2024-05-15:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_network_analytics:7.5.0:rollup_2024-06-10:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_network_analytics:7.5.0:rollup_2024-07-09:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_network_analytics:7.5.0:rollup_2024-08-13:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_network_analytics:7.5.0:rollup_2024-09-12:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_network_analytics:7.5.0:rollup_2024-10-15:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_network_analytics:7.5.0:rollup_2024-12-02:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_network_analytics:7.5.0:rollup_2025-01-24:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_network_analytics:7.5.1:-:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_network_analytics:7.5.1:rollup_2024-08-14:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_network_analytics:7.5.1:rollup_2024-09-18:*:*:*:*:*:*