CVE-2025-20256 is a high-severity vulnerability affecting Cisco Secure Network Analytics Manager and Virtual Manager, allowing authenticated, remote attackers to execute arbitrary commands as root due to insufficient input validation in the web-based management interface. The attack requires valid administrative credentials and has a CVSS score of 7.2. While the vulnerability has a high FAUCET Risk Score of 69/100, there is currently no public exploit code (Metasploit, Nuclei, ExploitDB) and no active exploitation reported. Community discussion and media coverage are also minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.4.1CPE matchmatch criteria | cpe:2.3:a:cisco:secure_network_analytics:7.4.1:*:*:*:*:*:*:* | ||
7.4.2CPE matchmatch criteria | cpe:2.3:a:cisco:secure_network_analytics:7.4.2:*:*:*:*:*:*:* | ||
7.5.0CPE matchmatch criteria | cpe:2.3:a:cisco:secure_network_analytics:7.5.0:-:*:*:*:*:*:* | ||
7.5.1CPE matchmatch criteria | cpe:2.3:a:cisco:secure_network_analytics:7.5.1:-:*:*:*:*:*:* | ||
7.5.2CPE matchmatch criteria | cpe:2.3:a:cisco:secure_network_analytics:7.5.2:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.