CVE-2025-20147 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, remote atta…
Medium CVSS: 5.4

CVE-2025-20147

A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, remote attacker to conduct a stored cross-site scripting attack (XSS) on an affected system. 

This vulnerability is due to improper sanitization of user input to the web-based management interface. An attacker could exploit this vulnerability by submitting a malicious script through the interface. A successful exploit could allow the attacker to conduct a stored XSS attack on the affected system.
Vendor
Cisco
Product
Catalyst Sd-wan Manager
CWE
CWE-79
Yayın Tarihi
2025-05-07 18:15:36
Güncelleme
2025-07-31 18:14:54
Source Identifier
psirt@cisco.com
KEV Date Added
-

Kategoriler

Referanslar