CVE-2025-20164
HIGHCisco Industrial Ethernet Switch Device Manager - Privilege Escalation
Title source: llmDescription
A vulnerability in the Cisco Industrial Ethernet Switch Device Manager (DM) of Cisco IOS Software could allow an authenticated, remote attacker to elevate privileges. This vulnerability is due to insufficient validation of authorizations for authenticated users. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to elevate privileges to privilege level 15. To exploit this vulnerability, the attacker must have valid credentials for a user account with privilege level 5 or higher. Read-only DM users are assigned privilege level 5.
References (1)
Core 1
Core References
Scores
CVSS v3
8.3
EPSS
0.0038
EPSS Percentile
59.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-862
Status
published
Products (50)
Cisco/IOS
15.0(2)EA
Cisco/IOS
15.0(2)EA1
Cisco/IOS
15.0(2)EK
Cisco/IOS
15.0(2)EK1
Cisco/IOS
15.0(2)SE8
Cisco/IOS
15.2(1)EY
Cisco/IOS
15.2(2)E
Cisco/IOS
15.2(2)E1
Cisco/IOS
15.2(2)E10
Cisco/IOS
15.2(2)E2
... and 40 more
Published
May 07, 2025
Tracked Since
Feb 18, 2026