Cisco Catalyst Center Unauthenticated API Access Vulnerability
TL;DR 📌
A high-severity vulnerability has been identified in the Cisco Catalyst Center, allowing unauthenticated remote attackers to read and modify proxy configuration settings via an unprotected API endpoint. This could disrupt internet traffic or allow interception of outbound traffic. Users are advised to upgrade to fixed software version 2.3.7.9 or later.
What happened 🕵️♂️
A vulnerability in the management API of Cisco Catalyst Center (formerly Cisco DNA Center) has been discovered. This issue stems from a lack of authentication on an API endpoint, enabling unauthenticated remote attackers to send requests that could read or modify the outgoing proxy configuration. Such exploitation could disrupt internet traffic or allow attackers to intercept outbound traffic.
Affected products 🖥️
The vulnerability affects all versions of Cisco Catalyst Center, regardless of device configuration.
Fixed software 🔧
Upgrade to the first fixed release in your train (or later):
| Release / Product | First Fixed Release | Notes |
|---|---|---|
| 1.0 | Initial public release. | |
| Cisco Catalyst Center | 2.3.7.9 | Earlier than 2.3.7.9 |
Workarounds 🧯
There are no workarounds available to address this vulnerability.
Risk in context 🎯
With a CVSS score of 7.3, this vulnerability is rated as High. The risk is significant due to its potential for exploitation by unauthenticated attackers, which could lead to unauthorized access to sensitive configuration settings. Organizations using affected products should prioritize applying the available software updates to reduce exposure.
Fast facts ⚡
- Vulnerability ID: CVE-2025-20210
- CVSS Score: 7.3 (High)
- Exploitation Potential: Unauthenticated remote access
- Impact: Possible disruption of internet traffic and interception of outbound traffic
- Fixed Release: 2.3.7.9
For leadership 🧭
Executive summary. Cisco Catalyst Center’s management API has an endpoint that requires no authentication and controls proxy settings, meaning anyone who can reach it could redirect or snoop on outbound network traffic. There is no workaround, so patching is the only fix and should be scheduled without delay.
Why it matters:
- The flaw sits in the outgoing proxy configuration API, which governs how the Catalyst Center itself routes its outbound connections, not just administrative access.
- No authentication is required, so any party with network reach to the API endpoint can read or alter proxy settings without credentials.
- Modifying proxy configuration could let an attacker intercept outbound traffic or disrupt the appliance’s internet connectivity.
- All versions of Cisco Catalyst Center are affected regardless of configuration, and no workaround exists, leaving upgrade as the only mitigation.
Now / Next / Later:
- Now: Identify every Cisco Catalyst Center (formerly DNA Center) instance in your estate and check whether its management API is reachable from untrusted networks.
- Next: Upgrade all affected Catalyst Center deployments to release 2.3.7.9 or later during the next available change window, since no workaround is offered.
- Later: Add Catalyst Center management API interfaces to your network segmentation and access-control review process so unauthenticated endpoints are never exposed beyond trusted management networks.