CVE-2025-20341

HIGH

A vulnerability in Cisco Catalyst Center Virtual Appliance could allow an authenticated, remote attacker to elevate privileges to Administrator on an affected system. This vulnerability is due t...

Affects 0 products across 3 vendors.

BCS6.26
CVSS 3.18.8
EPSS0.5%
Percentile40th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, low privileges required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-284: Improper Access Control

Software does not restrict or incorrectly restricts access to a resource.

Related Attack Patterns (CAPEC)
CAPEC-478 Modification of Windows Service Configuration
via CWE-284
CAPEC-479 Malicious Root Certificate
via CWE-284
CAPEC-546 Incomplete Data Deletion in a Multi-Tenant Environment
via CWE-284
CAPEC-550 Install New Service
via CWE-284
CAPEC-551 Modify Existing Service
via CWE-284
Show all 17

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A vulnerability in Cisco Catalyst Center Virtual Appliance allows an authenticated, remote attacker to elevate privileges to Administrator due to insufficient validation of user-supplied input.

BSID: BS-2025-GLOBAL-236237-H • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2025-20341?
A vulnerability in Cisco Catalyst Center Virtual Appliance allows an authenticated, remote attacker to elevate privileges to Administrator due to insufficient validation of user-supplied input.
What is the CVSS score for CVE-2025-20341?
CVE-2025-20341 has CVSS 8.8 (High). Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. EPSS: 0.5%.
Is CVE-2025-20341 actively exploited?
No confirmed active exploitation of CVE-2025-20341 as of 2026-05-30.
How do I remediate CVE-2025-20341?
Priority: IMMEDIATE. Advisory: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-catc-priv-esc-VS8EeCuX PSIRT: [email protected]
What systems are affected by CVE-2025-20341?
CVE-2025-20341 affects: Catalyst, Cisco, Valid.
Vulnerability Details
CVE IDCVE-2025-20341
BSIDBS-2025-GLOBAL-236237-H BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Published2025-11-13
Last Modified2026-04-15
ICS Relevance70%
Weakness (CWE)
Domains
NETWORK-INFRA
SourceNVD
Official Description

A vulnerability in Cisco Catalyst Center Virtual Appliance could allow an authenticated, remote attacker to elevate privileges to Administrator on an affected system. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted HTTP request to an affected system. A successful exploit could allow the attacker to perform unauthorized modifications to the system, including creating new user accounts or elevating their own privileges on an affected system. To exploit this vulnerability, the attacker must have valid credentials for a user account with at least the role of Observer.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

An attacker could exploit this vulnerability by submitting a crafted HTTP request to an affected system, leading to unauthorized privilege escalation.

Exploitation Likelihood: HIGH

Affected Products
VendorProductFixed Version
Catalyst —
Cisco —
Valid —
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 254 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash584922f4fff81274ffe27015a437bb8e148a9ef85055eb71df293cd90ac2b8c222c0955bac07c482d02aeb15e19e70785b894722a30b85464149d7f1dd3de23f
Related CVEs affecting Catalyst
CVE-2026-26009 9.9 Catalyst is a platform built for enterprise game server hosts, game communiti... CVE-2026-20086 8.6 A vulnerability in the processing of Control and Provisioning of Wireless Acc... CVE-2026-20224 8.6 A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-W... CVE-2026-20084 8.6 A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could a... CVE-2025-40920 8.6 Catalyst::Authentication::Credential::HTTP versions 1.018 and earlier for Per...
View all Catalyst CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →