Cisco Secure Network Analytics Manager API Authorization Vulnerability
TL;DR 📌
A medium-severity vulnerability has been identified in the Cisco Secure Network Analytics Manager API, which could allow authenticated low-privileged users to generate fraudulent findings. Cisco has released updates to address this issue, but no workarounds are available.
What happened 🕵️♂️
A vulnerability in the API subsystem of Cisco Secure Network Analytics Manager and Cisco Secure Network Analytics Virtual Manager could allow an authenticated, remote attacker with low privileges to create fraudulent findings. This vulnerability arises from insufficient authorization enforcement on a specific API. An attacker could exploit this by authenticating as a low-privileged user and making crafted API calls, potentially obfuscating legitimate findings in analytics reports or generating false alarms and alerts.
Affected products 🖥️
The following products are affected by this vulnerability:
- Cisco Secure Network Analytics Manager
- Cisco Secure Network Analytics Virtual Manager
Products confirmed not vulnerable include:
- Secure Cloud Analytics
- Secure Network Analytics Data Store
- Secure Network Analytics Flow Collector
- Secure Network Analytics Flow Sensor
- Secure Network Analytics UDP Director
- Secure Network Analytics Virtual Data Store
- Secure Network Analytics Virtual Flow Collector
- Secure Network Analytics Virtual Flow Sensor
- Secure Network Analytics Virtual UDP Director
Fixed software 🔧
Upgrade to at least the first fixed release in your train (or later):
| Product / Release Train | First Fixed Release | Notes |
|---|---|---|
| ISE / ISE-PIC 1.0 | Initial public release. |
Workarounds 🧯
There are no workarounds available to address this vulnerability.
Risk in context 🎯
The vulnerability has a CVSS score of 6.5, categorized as medium severity. While it does not allow for complete system compromise, the potential for generating false findings and alerts could lead to significant operational disruptions and misinformed decision-making.
Fast facts ⚡
- Vulnerability ID: CVE-2025-20257
- CVSS Score: 6.5 (Medium)
- Affected Products: Cisco Secure Network Analytics Manager, Cisco Secure Network Analytics Virtual Manager
- Fixed Software: 7.5.2 SMC ROLLUP20250416-01
For leadership 🧭
Executive summary. An authenticated user with only low-level access to Secure Network Analytics Manager can manipulate the analytics API to plant fake findings or bury genuine ones, undermining trust in the SOC’s alerting. There is no workaround, so this should be scheduled for patching in the next maintenance window rather than treated as an emergency.
Why it matters:
- The flaw sits in the API subsystem of Secure Network Analytics Manager and Virtual Manager, which is the console analysts rely on for findings and alerts.
- Insufficient authorization checks mean any authenticated low-privileged account, not just admins, can craft API calls that inject fraudulent findings.
- Attackers with this level of access could obscure real threats in analytics reports or flood the console with false alarms, delaying genuine incident response.
- Sensor and collector components (Flow Collector, Flow Sensor, Data Store, UDP Director and their virtual equivalents) are confirmed unaffected, so the exposure is limited to the Manager tier.
Now / Next / Later:
- Now: Review who currently holds low-privileged accounts on Secure Network Analytics Manager or Virtual Manager and confirm none are unaccounted for or shared.
- Next: Upgrade affected Manager and Virtual Manager instances to 7.5.2 SMC ROLLUP20250416-01 or later in the next scheduled change window, since no workaround exists.
- Later: Tighten role-based access reviews for Secure Network Analytics Manager so low-privileged accounts are periodically audited against least-privilege expectations.