CVE-2025-20147
Cisco SD-WAN vManage Stored Cross-Site Scripting Vulnerability
Description
A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, remote attacker to conduct a stored cross-site scripting attack (XSS) on an affected system. This vulnerability is due to improper sanitization of user input to the web-based management interface. An attacker could exploit this vulnerability by submitting a malicious script through the interface. A successful exploit could allow the attacker to conduct a stored XSS attack on the affected system.
Weakness: CWE-79
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | Cisco Catalyst SD-WAN Manager | Network & Security Management | cna-assigner |
Vendor-reported products (1)
- Cisco · Cisco Catalyst SD-WAN Manager
Vendor advisory
Cisco Catalyst SD-WAN Manager Stored Cross-Site Scripting Vulnerability
Cisco’s rating: Medium (advisory CVSS 5.4) · Published May 7, 2025
Bug ID: CSCwm49535
The vendor’s rating applies to the whole advisory and can differ from this CVE’s own CVSS severity. Where this comes from