CVE-2025-20339

Cisco SD-WAN vEdge Software Access Control List Bypass Vulnerability

Severity
Medium 5.8
CVSS 3.1
Exploited
Not listed
EPSS
0.003
21.6th percentile
Discovered by
Third party
Published by the vendor
Published
Sep 24, 2025
Assigned by cisco

Description

A vulnerability in the access control list (ACL) processing of IPv4 packets of Cisco SD-WAN vEdge Software could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to the improper enforcement of the implicit deny all at the end of a configured ACL. An attacker could exploit this vulnerability by attempting to send unauthorized traffic to an interface on an affected device. A successful exploit could allow the attacker to bypass an ACL on the affected device.

Weakness: CWE-284

Affected products

Vendor Product Category Matched by
Cisco Cisco SD-WAN vEdge Routing & Switching cna-assigner
Vendor-reported affected versions (2)
  • Cisco · Cisco SD-WAN vEdge Cloud
  • Cisco · Cisco SD-WAN vEdge Router