Cisco Catalyst Center Virtual Appliance HTTP Open Redirect Vulnerability
TL;DR 📌
A medium-severity HTTP open redirect vulnerability has been identified in the Cisco Catalyst Center Virtual Appliance. This flaw could allow unauthenticated attackers to redirect users to malicious web pages. Cisco has released fixed software versions, but there are no workarounds available.
What happened 🕵️♂️
A vulnerability in the web-based management interface of the Cisco Catalyst Center Virtual Appliance has been discovered. This issue arises from improper input validation of HTTP request parameters, enabling an unauthenticated remote attacker to intercept and modify HTTP requests. If exploited, this could redirect users to malicious web pages, posing a security risk.
Affected products 🖥️
The vulnerability affects the Cisco Catalyst Center Virtual Appliance running on VMware ESXi, regardless of device configuration. Cisco has confirmed that the following products are not vulnerable:
- Catalyst Center hardware appliances
- Catalyst Center Virtual Appliance on Amazon Web Services (AWS)
Fixed software 🔧
Upgrade to the first fixed release in your train (or later):
| Release / Product | First Fixed Release | Notes |
|---|---|---|
| 3.1 | Not vulnerable | |
| 1.0 | Initial public release. | |
| Cisco Catalyst Center | 2.3.7.10-VA | Earlier than 2.3.7.3-VA |
Workarounds 🧯
There are no workarounds that address this vulnerability.
Risk in context 🎯
The highest CVSS score for this vulnerability is 4.7, categorizing it as Medium severity. While there is no direct impact on confidentiality, integrity, or availability, the potential for redirection to malicious sites poses a risk to users. Organizations should prioritize upgrading to the fixed software to mitigate this risk.
Fast facts ⚡
- Vulnerability: HTTP Open Redirect
- CVSS Score: 4.7 (Medium)
- Exploitation: Unauthenticated remote attackers can exploit this vulnerability.
- No workarounds available: Immediate action required to upgrade.
For leadership 🧭
Executive summary. Cisco’s Catalyst Center Virtual Appliance running on VMware ESXi contains an open redirect flaw in its management web interface that could be used to send administrators or users to attacker-controlled pages, with no compensating workaround. This is a medium-severity issue rather than an emergency, but since patching is the only fix, it should be scheduled into the next available maintenance window.
Why it matters:
- The flaw sits in the web-based management interface of Catalyst Center Virtual Appliance, the console administrators use to manage network infrastructure, making it a plausible phishing or credential-harvesting vector against your own admin staff.
- Only the ESXi-hosted Virtual Appliance is affected; hardware appliances and the AWS-hosted Virtual Appliance are confirmed not vulnerable, so exposure depends on which deployment form you run.
- No authentication is required to exploit the redirect, and Cisco has published no workaround, so the fixed release is the only mitigation.
- Versions earlier than 2.3.7.3-VA on ESXi remain exposed until upgraded to 2.3.7.10-VA or later; the 3.1 train is not vulnerable.
Now / Next / Later:
- Now: Confirm whether you run Catalyst Center Virtual Appliance on VMware ESXi and, if so, check the installed version against 2.3.7.3-VA to determine exposure.
- Next: Schedule an upgrade of any exposed ESXi-hosted Catalyst Center Virtual Appliance to 2.3.7.10-VA or later during the next maintenance window, since no workaround exists.
- Later: Standardise on tracking Catalyst Center release trains against Cisco’s fixed-software table so future advisories affecting the ESXi Virtual Appliance are triaged quickly against your running versions.