CVE-2025-20118

CVSS 3.1 Score 4.4 of 10 (medium)

Details

Published Feb 26, 2025
CWE ID 212

Summary

CVE-2025-20118 is a vulnerability affecting the internal system processes of Cisco APIC. This issue allows authenticated, local attackers with valid administrative credentials to access sensitive information on affected devices. The vulnerability arises from insufficient masking of sensitive information displayed through system CLI commands. An attacker could exploit this flaw using reconnaissance techniques at the device CLI, potentially gaining access to confidential data that could be utilized for further attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Cisco Application Policy Infrastructure Controller

Affected Vendors

  • Cisco