Cisco Catalyst Center Virtual Appliance Privilege Escalation Vulnerability

🚨 SEVERITY: HIGH — CVSS 8.8 Security Advisory

TL;DR 📌

A privilege escalation vulnerability has been identified in the Cisco Catalyst Center Virtual Appliance, allowing authenticated attackers to elevate their privileges to Administrator. The highest CVSS score for this vulnerability is 8.8, categorized as High severity. No workarounds are available, but fixed software releases are provided.

What happened 🕵️‍♂️

A vulnerability in the Cisco Catalyst Center Virtual Appliance could allow an authenticated, remote attacker to elevate their privileges to Administrator on an affected system. This issue arises from insufficient validation of user-supplied input. An attacker with valid credentials for a user account with at least the Observer role could exploit this vulnerability by sending a crafted HTTP request, potentially allowing unauthorized modifications to the system.

Affected products 🖥️

The vulnerability affects the Cisco Catalyst Center Virtual Appliance running on VMware ESXi, regardless of device configuration. Notably, it does not impact Catalyst Center hardware appliances or the Catalyst Center Virtual Appliance on Amazon Web Services (AWS).

Fixed software 🔧

Upgrade to the first fixed release in your train (or later):

Release / Product First Fixed Release Notes
3.1 Not vulnerable
1.0 Initial public release.
Cisco Catalyst Center 2.3.7.10-VA 2.3.7.3-VA and later

Workarounds 🧯

There are no workarounds available to mitigate this vulnerability.

Risk in context 🎯

With a CVSS score of 8.8, this vulnerability poses a significant risk. The requirement for valid credentials limits exposure to authenticated users, but the potential for privilege escalation could lead to serious unauthorized system modifications.

Fast facts ⚡

  • Vulnerability ID: CVE-2025-20341
  • Severity: High (CVSS 8.8)
  • Exploitation: Requires valid user credentials
  • Impact: Unauthorized modifications, including privilege escalation

For leadership 🧭

Executive summary. Any low-privilege account on a Cisco Catalyst Center Virtual Appliance (on VMware ESXi) can be turned into a full administrator, giving that user unrestricted control over network management. Because there is no workaround, this needs patching on the next available change window rather than deferred indefinitely.

Why it matters:

  • Observer-role accounts, normally read-only, can be used to send a crafted HTTP request that grants full Administrator rights on the Catalyst Center Virtual Appliance.
  • Catalyst Center administers network-wide configuration, so an escalated account could make unauthorized changes across managed infrastructure.
  • Only the VMware ESXi virtual appliance is affected; hardware appliances and the AWS virtual appliance are not exposed to this issue.
  • With no workaround published, the only mitigation is upgrading to a fixed release, so exposure persists until the patch is applied.

Now / Next / Later:

  • Now: Identify every Cisco Catalyst Center Virtual Appliance running on VMware ESXi and check its current release against the fixed versions.
  • Next: Schedule an upgrade to Catalyst Center release 2.3.7.10-VA (or the first fixed release in your train) during the next change window, since no workaround exists.
  • Later: Review who holds Observer-level accounts on Catalyst Center and tighten credential issuance and rotation, since this flaw shows low-privilege access alone can be a path to full administrative control.