CVE-2025-20178
MEDIUMDescription
A vulnerability in the web-based management interface of Cisco Secure Network Analytics could allow an authenticated, remote attacker with valid administrative credentials to execute arbitrary commands as root on the underlying operating system. This vulnerability is due to insufficient integrity checks within device backup files. An attacker with valid administrative credentials could exploit this vulnerability by crafting a malicious backup file and restoring it to an affected device. A successful exploit could allow the attacker to obtain shell access on the underlying operating system with the privileges of root.
Is your site exposed to CVE-2025-20178?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| cisco | secure_network_analytics |
| cisco | secure_network_analytics |
| cisco | secure_network_analytics |
| cisco | secure_network_analytics |
| cisco | secure_network_analytics |
| cisco | secure_network_analytics |
| cisco | secure_network_analytics |
| cisco | secure_network_analytics |
| cisco | secure_network_analytics |
| cisco | secure_network_analytics |
| cisco | secure_network_analytics |
| cisco | secure_network_analytics |
| cisco | secure_network_analytics |
| cisco | secure_network_analytics |
| cisco | secure_network_analytics |
| cisco | secure_network_analytics |
| cisco | secure_network_analytics |
| cisco | secure_network_analytics |
| cisco | secure_network_analytics |
References
Frequently Asked Questions
What is CVE-2025-20178? +
How severe is CVE-2025-20178? +
What products are affected by CVE-2025-20178? +
How do I check if I'm vulnerable to CVE-2025-20178? +
Related Vulnerabilities
DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase enterprise token handling can let TokenFilter#doFilter() …
OpenLearnX is an open-source, decentralized learning and assessment platform. Prior to 2.0.4, a critical authentication vulnerability was identified in OpenLearnX …
Hyperbridge is a hyper-scalable coprocessor for verifiable, cross-chain interoperability. A critical vulnerability was discovered in the ismp-grandpa crate, that allowed …
aes-gcm is a pure Rust implementation of the AES-GCM. In decrypt_in_place_detached, the decrypted ciphertext (which is the correct ciphertext) is …
Improper verification of the digital signature in ksojscore.dll in Kingsoft WPS Office in versions equal or less than 12.1.0.18276 on …
xml-crypto is an XML digital signature and encryption library for Node.js. An attacker may be able to exploit a vulnerability …