CVE-2025-20114 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

A vulnerability in the API of Cisco Unified Intelligence Center could allow an authenticated, remote attacker to perform a horizontal privilege escalation attac…
Medium CVSS: 4.3

CVE-2025-20114

A vulnerability in the API of Cisco Unified Intelligence Center could allow an authenticated, remote attacker to perform a horizontal privilege escalation attack on an affected system.

This vulnerability is due to insufficient validation of user-supplied parameters in API requests. An attacker could exploit this vulnerability by submitting crafted API requests to an affected system to execute an insecure direct object reference attack. A successful exploit could allow the attacker to access specific data that is associated with different users on the affected system.
Vendor
Cisco
Product
Unified Intelligence Center
CWE
CWE-639
Yayın Tarihi
2025-05-21 17:15:55
Güncelleme
2025-07-22 14:41:40
Source Identifier
psirt@cisco.com
KEV Date Added
-

Kategoriler

Referanslar