CVE-2025-20377: Cisco Unified Intelligence Center API Information Disclosure Vulnerability
A vulnerability in the API subsystem of Cisco Unified Intelligence Center could allow an authenticated, remote attacker to obtain sensitive information from an affected system. This vulnerability is due to improper validation of requests to certain API endpoints. An attacker could exploit this vulnerability by sending a valid request to a specific API endpoint within the affected system. A successful exploit could allow a low-privileged user to view sensitive information on the affected system that should be restricted. To exploit this vulnerability, the attacker must have valid user credentials on the affected system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20377?
CVE-2025-20377 has a severity rating that indicates a significant impact on the confidentiality of sensitive information.
How do I fix CVE-2025-20377?
To fix CVE-2025-20377, update the Cisco Unified Intelligence Center to the latest version that addresses this vulnerability.
What type of attack is possible with CVE-2025-20377?
An authenticated remote attacker can exploit CVE-2025-20377 to obtain sensitive information from the affected system.
What products are affected by CVE-2025-20377?
CVE-2025-20377 affects the Cisco Unified Intelligence Center API subsystem.
What is the cause of CVE-2025-20377?
CVE-2025-20377 is caused by improper validation of requests to certain API endpoints.