CVE-2025-20293

A vulnerability in the Day One setup process of Cisco IOS XE Software for Catalyst 9800 Series Wireless Controllers for Cloud (9800-CL) could allow an unauthenticated, remote attacker to access the pu

Severity
Medium 5.3
CVSS 3.1
Remote · no auth what this means
Exploited
Not listed
EPSS
0.002
8.7th percentile
Discovered by
Vendor
Vendor-published field
Published
Sep 24, 2025
Assigned by cisco

Description

A vulnerability in the Day One setup process of Cisco IOS XE Software for Catalyst 9800 Series Wireless Controllers for Cloud (9800-CL) could allow an unauthenticated, remote attacker to access the public-key infrastructure (PKI) server that is running on an affected device. This vulnerability is due to incomplete cleanup upon completion of the Day One setup process. An attacker could exploit this vulnerability by sending Simple Certificate Enrollment Protocol (SCEP) requests to an affected device. A successful exploit could allow the attacker to request a certificate from the virtual wireless controller and then use the acquired certificate to join an attacker-controlled device to the virtual wireless controller.

Weakness: CWE-459

Affected products

Vendor Product Category Matched by
Cisco Cisco IOS XE Software Routing & Switching cna-assigner
Vendor-reported products (1)
  • Cisco · Cisco IOS XE Software

Vendor advisory

cisco-sa-9800cl-openscep-SB4xtxzP

Cisco IOS XE Software for Catalyst 9800 Series Wireless Controller for Cloud Unauthenticated Access to Certificate Enrollment Service Vulnerability

Cisco’s rating: Medium (advisory CVSS 5.3) · Published Sep 24, 2025

Bug ID: CSCwh91048

The vendor’s rating applies to the whole advisory and can differ from this CVE’s own CVSS severity. Where this comes from

Something wrong here?