Cisco Catalyst Center Privilege Escalation Vulnerability
TL;DR 📌
A privilege escalation vulnerability has been identified in Cisco Catalyst Center, allowing authenticated users to perform actions requiring Administrator privileges. The highest CVSS score is 4.3 (Medium). Users are advised to upgrade to fixed software releases as there are no workarounds available.
What happened 🕵️♂️
A vulnerability in Cisco Catalyst Center could enable an authenticated, remote attacker to execute operations that should be restricted to Administrator privileges. This issue arises from improper role-based access control (RBAC). An attacker with valid read-only user credentials could exploit this vulnerability by logging in and modifying certain policy configurations reserved for the Administrator role.
Affected products 🖥️
The vulnerability affects Cisco Catalyst Center, including both virtual and hardware appliances, regardless of device configuration.
Fixed software 🔧
Upgrade to the first fixed release in your train (or later):
| Release / Product | First Fixed Release | Notes |
|---|---|---|
| 2.3.7 and earlier | 2.3.7.10 | |
| 3.1 | Not affected | |
| 1.0 | Initial public release. | |
| Cisco Catalyst Center | 2.3.7.10 | 2.3.7 and earlier |
Workarounds 🧯
There are no workarounds available for this vulnerability.
Risk in context 🎯
With a CVSS score of 4.3, this vulnerability is rated as Medium risk. While it requires authenticated access, the potential for an attacker to escalate privileges poses a significant threat to the integrity of system configurations.
Fast facts ⚡
- Vulnerability: Cisco Catalyst Center Privilege Escalation
- CVSS Score: 4.3 (Medium)
- Exploitation: Requires valid user credentials
- Workarounds: None available
- Fixed Software: Upgrade to 2.3.7.10 if on 2.3.7 or earlier
For leadership 🧭
Executive summary. Any account with basic read-only access to Cisco Catalyst Center can currently alter administrator-level policy settings, undermining the intended separation of duties. There’s no workaround, so remediation depends entirely on scheduling the software upgrade.
Why it matters:
- Catalyst Center centrally manages network policy across an organisation’s switching and routing estate, so unauthorised policy changes here can propagate widely
- The flaw requires only valid read-only credentials, a tier of access typically granted to far more staff than full administrator rights
- No workaround exists, meaning exposure persists on any unpatched 2.3.7 or earlier release until the software is upgraded
- Both virtual and hardware Catalyst Center appliances are affected regardless of configuration, so deployment specifics don’t reduce exposure
Now / Next / Later:
- Now: Identify every Catalyst Center instance in your estate and check its release version against 2.3.7 and earlier to confirm exposure.
- Next: Upgrade affected Catalyst Center deployments to 2.3.7.10 or later during your next scheduled change window, since no interim workaround is available.
- Later: Review who holds read-only accounts on Catalyst Center and tighten provisioning so low-privilege access isn’t handed out more broadly than necessary.