CVE-2025-20147

Cisco SD-WAN vManage Stored Cross-Site Scripting Vulnerability

Severity
Medium 5.4
CVSS 3.1
Exploited
Not listed
EPSS
0.003
24.9th percentile
Discovered by
Third party
Vendor-published field
Published
May 7, 2025
Assigned by cisco

Description

A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, remote attacker to conduct a stored cross-site scripting attack (XSS) on an affected system.  This vulnerability is due to improper sanitization of user input to the web-based management interface. An attacker could exploit this vulnerability by submitting a malicious script through the interface. A successful exploit could allow the attacker to conduct a stored XSS attack on the affected system.

Weakness: CWE-79

Affected products

Vendor Product Category Matched by
Cisco Cisco Catalyst SD-WAN Manager Network & Security Management cna-assigner
Vendor-reported products (1)
  • Cisco · Cisco Catalyst SD-WAN Manager

Something wrong here?