CVE-2025-20355: Cisco Catalyst Center Software HTTP Open Redirect Vulnerability
A vulnerability in the web-based management interface of Cisco Catalyst Center Virtual Appliance could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of HTTP request parameters. An attacker could exploit this vulnerability by intercepting and modifying an HTTP request from a user. A successful exploit could allow the attacker to redirect the user to a malicious web page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20355?
CVE-2025-20355 has been classified as a medium severity vulnerability.
How do I fix CVE-2025-20355?
To remediate CVE-2025-20355, update the Cisco Catalyst Center Virtual Appliance to the latest version that contains the patch.
What are the risks associated with CVE-2025-20355?
CVE-2025-20355 allows an unauthenticated, remote attacker to redirect users to a malicious web page, potentially leading to phishing or malware.
Is CVE-2025-20355 easy to exploit?
Yes, CVE-2025-20355 can be exploited easily due to improper input validation of HTTP request parameters.
Who is impacted by CVE-2025-20355?
Organizations using the Cisco Catalyst Center Virtual Appliance are impacted by CVE-2025-20355.