CVE-2025-20126
CVSS 3.1 Score 4.8 of 10 (medium)
Details
Summary
CVE-2025-20126 is a vulnerability affecting Cisco ThousandEyes Endpoint Agent for macOS and RoomOS. The issue lies in the certification validation routines, which fail to properly verify certificates for hosted metrics services. An unauthenticated, remote attacker can exploit this vulnerability by intercepting network traffic with a crafted certificate, enabling them to masquerade as a trusted host and monitor or manipulate metrics information exchanged between the remote metrics service and the affected client. This could potentially lead to confidential information disclosure or unauthorized modifications.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.