CVE-2025-20157 describes a medium-severity vulnerability in Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage) related to improper certificate validation within its Smart Licensing feature. An unauthenticated, remote attacker in a privileged network position could exploit this to intercept traffic and gain access to sensitive information, including credentials for Cisco cloud services. The CVSS score is 5.9, indicating a high impact on confidentiality with high attack complexity. Currently, there is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
17.2.4CPE matchmatch criteria | cpe:2.3:a:cisco:catalyst_sd-wan_manager:17.2.4:*:*:*:*:*:*:* | ||
17.2.5CPE matchmatch criteria | cpe:2.3:a:cisco:catalyst_sd-wan_manager:17.2.5:*:*:*:*:*:*:* | ||
17.2.6CPE matchmatch criteria | cpe:2.3:a:cisco:catalyst_sd-wan_manager:17.2.6:*:*:*:*:*:*:* | ||
17.2.7CPE matchmatch criteria | cpe:2.3:a:cisco:catalyst_sd-wan_manager:17.2.7:*:*:*:*:*:*:* | ||
17.2.8CPE matchmatch criteria | cpe:2.3:a:cisco:catalyst_sd-wan_manager:17.2.8:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.