Cisco has disclosed a high-severity privilege escalation vulnerability, tracked as CVE-2025-20341, affecting the Cisco Catalyst Center Virtual Appliance. The flaw allows an authenticated, remote attacker with at least Observer-level credentials to elevate privileges to Administrator by submitting a crafted HTTP request due to insufficient validation of user-supplied input. Successful exploitation could enable unauthorized modifications, including creating new user accounts or elevating existing privileges, posing a significant risk to affected systems.
Security advisories from both Cisco and the Canadian Centre for Cyber Security urge administrators to review the official guidance and apply updates or mitigations to address the vulnerability. The issue impacts Catalyst Center Virtual Appliance versions prior to 2.3.7.10-VA and is remotely exploitable. Organizations using affected versions are strongly advised to update their systems promptly to prevent potential exploitation.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Cisco published a security advisory for a Cisco Catalyst Center Arbitrary File Read Vulnerability. The advisory represents a new vulnerability disclosure affecting Cisco Catalyst Center, distinct from the previously tracked CVE-2025-20341 privilege escalation issue.
The Canadian Centre for Cyber Security published alert AV25-759 referencing Cisco's security advisory for CVE-2025-20341. This reflects official downstream government notice of the vulnerability.
Cisco disclosed a high-severity privilege escalation vulnerability, tracked as CVE-2025-20341, affecting Cisco Catalyst Center Virtual Appliance. The issue was publicly listed in vulnerability and advisory reporting on November 13, 2025.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
4 references tracked. Mallory keeps watching after this page renders.
sec.cloudapps.cisco.com
Open sourcesecurityonline.info
Open sourcecyber.gc.ca
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.