CVE-2025-20147
Cisco SD-WAN vManage Stored Cross-Site Scripting Vulnerability
Severity
Medium 5.4
CVSS 3.1
Exploited
Not listed
EPSS
0.003
24.9th percentile
Discovered by
Third party
Vendor-published field
Published
May 7, 2025
Assigned by cisco
Description
A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, remote attacker to conduct a stored cross-site scripting attack (XSS) on an affected system. This vulnerability is due to improper sanitization of user input to the web-based management interface. An attacker could exploit this vulnerability by submitting a malicious script through the interface. A successful exploit could allow the attacker to conduct a stored XSS attack on the affected system.
Weakness: CWE-79
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | Cisco Catalyst SD-WAN Manager | Network & Security Management | cna-assigner |
Vendor-reported products (1)
- Cisco · Cisco Catalyst SD-WAN Manager