CVE-2025-20164

HIGH

Cisco Industrial Ethernet Switch Device Manager - Privilege Escalation

Title source: llm
STIX 2.1

Description

A vulnerability in the Cisco Industrial Ethernet Switch Device Manager (DM) of Cisco IOS Software could allow an authenticated, remote attacker to elevate privileges. This vulnerability is due to insufficient validation of authorizations for authenticated users. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to elevate privileges to privilege level 15. To exploit this vulnerability, the attacker must have valid credentials for a user account with privilege level 5 or higher. Read-only DM users are assigned privilege level 5.

Scores

CVSS v3 8.3
EPSS 0.0038
EPSS Percentile 59.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-862
Status published
Products (50)
Cisco/IOS 15.0(2)EA
Cisco/IOS 15.0(2)EA1
Cisco/IOS 15.0(2)EK
Cisco/IOS 15.0(2)EK1
Cisco/IOS 15.0(2)SE8
Cisco/IOS 15.2(1)EY
Cisco/IOS 15.2(2)E
Cisco/IOS 15.2(2)E1
Cisco/IOS 15.2(2)E10
Cisco/IOS 15.2(2)E2
... and 40 more
Published May 07, 2025
Tracked Since Feb 18, 2026