CVE-2025-20118
CVSS 3.1 Score 4.4 of 10 (medium)
Details
Published Feb 26, 2025
CWE ID 212
Summary
CVE-2025-20118 is a vulnerability affecting the internal system processes of Cisco APIC. This issue allows authenticated, local attackers with valid administrative credentials to access sensitive information on affected devices. The vulnerability arises from insufficient masking of sensitive information displayed through system CLI commands. An attacker could exploit this flaw using reconnaissance techniques at the device CLI, potentially gaining access to confidential data that could be utilized for further attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Cisco Application Policy Infrastructure Controller
Affected Vendors
- Cisco