CVE-2025-20190

A vulnerability in the lobby ambassador web interface of Cisco IOS XE Wireless Controller Software could allow an authenticated, remote attacker to remove arbitrary users that are defined on an affect

Severity
Medium 6.5
CVSS 3.1
Remote, needs privileges or user interaction what this means
Exploited
Not listed
EPSS
0.004
33.8th percentile
Discovered by
Vendor
Vendor-published field
Published
May 7, 2025
Assigned by cisco

Description

A vulnerability in the lobby ambassador web interface of Cisco IOS XE Wireless Controller Software could allow an authenticated, remote attacker to remove arbitrary users that are defined on an affected device. This vulnerability is due to insufficient access control of actions executed by lobby ambassador users. An attacker could exploit this vulnerability by logging in to an affected device with a lobby ambassador user account and sending crafted HTTP requests to the API. A successful exploit could allow the attacker to delete arbitrary user accounts on the device, including users with administrative privileges. Note: This vulnerability is exploitable only if the attacker obtains the credentials for a lobby ambassador account. This account is not configured by default.

Weakness: CWE-284

Affected products

Vendor Product Category Matched by
Cisco Cisco IOS XE Software Routing & Switching cna-assigner
Vendor-reported products (1)
  • Cisco · Cisco IOS XE Software

Vendor advisory

cisco-sa-ewlc-user-del-hQxMpUDj

Cisco IOS XE Wireless Controller Software Unauthorized User Deletion Vulnerability

Cisco’s rating: Medium (advisory CVSS 6.5) · Published May 7, 2025

Bug ID: CSCwm35433

The vendor’s rating applies to the whole advisory and can differ from this CVE’s own CVSS severity. Where this comes from

Something wrong here?