CVE-2025-20349 is a critical command injection vulnerability in the REST API of Cisco Catalyst Center. This flaw allows an authenticated, remote attacker with at least Observer role credentials to execute arbitrary commands as the root user within a restricted container due to insufficient input validation. The vulnerability has a CVSS score of 8.8 (HIGH), indicating a high severity. Exploitation is relatively easy, requiring only valid credentials and a crafted API request, leading to potential complete compromise of confidentiality, integrity, and availability. Currently, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed in CISA's KEV catalog. However, there is some community discussion and media coverage, suggesting awareness of the vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.3.7.10CPE matchmatch criteria | cpe:2.3:a:cisco:catalyst_center:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.