CVE-2025-20164
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
07/05/2025
Last modified:
15/04/2026
Description
A vulnerability in the Cisco Industrial Ethernet Switch Device Manager (DM) of Cisco IOS Software could allow an authenticated, remote attacker to elevate privileges.<br />
<br />
This vulnerability is due to insufficient validation of authorizations for authenticated users. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to elevate privileges to privilege level 15.<br />
<br />
To exploit this vulnerability, the attacker must have valid credentials for a user account with privilege level 5 or higher. Read-only DM users are assigned privilege level 5.
Impact
Base Score 3.x
8.30
Severity 3.x
HIGH



