CVE-2025-20257

Cisco Secure Network Analytics API Authorization Vulnerability

Severity
Medium 6.5
CVSS 3.1
Remote, needs privileges or user interaction what this means
Exploited
Not listed
EPSS
0.003
23.3th percentile
Discovered by
Vendor
Vendor-published field
Published
May 21, 2025
Assigned by cisco

Description

A vulnerability in an API subsystem of Cisco Secure Network Analytics Manager and Cisco Secure Network Analytics Virtual Manager could allow an authenticated, remote attacker with low privileges to generate fraudulent findings that are used to generate alarms and alerts on an affected product. Thi vulnerability is due to insufficient authorization enforcement on a specific API. An attacker could exploit this vulnerability by authenticating as a low-privileged user and performing API calls with crafted input. A successful exploit could allow the attacker to obfuscate legitimate findings in analytics reports or create false indications with alarms and alerts on an affected device.

Weakness: CWE-863

Affected products

Vendor Product Category Matched by
Cisco Cisco Secure Network Analytics (Stealthwatch) Threat Detection & Sandbox cna-assigner
Vendor-reported products (1)
  • Cisco · Cisco Secure Network Analytics

Vendor advisory

cisco-sa-sna-apiacv-4B6X5ysw

Cisco Secure Network Analytics Manager API Authorization Vulnerability

Cisco’s rating: Medium (advisory CVSS 6.5) · Published May 21, 2025

Bug ID: CSCwo49519

The vendor’s rating applies to the whole advisory and can differ from this CVE’s own CVSS severity. Where this comes from

Something wrong here?