Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Cisco Catalyst Center Vulnerability Let Attackers Escalate Priveleges

A serious security flaw in Cisco Catalyst Center Virtual Appliance has been discovered that allows attackers with low-level access to gain full administrator control over affected systems.

A serious security flaw in Cisco Catalyst Center Virtual Appliance has been discovered that allows attackers with low-level access to gain full administrator control over affected systems.

The vulnerability, tracked as CVE-2025-20341, impacts virtual appliances running on VMware ESXi and carries a high severity rating with a CVSS score of 8.8.

This flaw poses a major risk to organizations using these systems for and monitoring.

The vulnerability stems from poor input validation within the system. When users submit data through web requests, the software fails to properly check and verify the information.

This oversight creates an opportunity for attackers to send specially designed HTTP requests that trick the system into granting them higher privileges.

The attack can be carried out remotely over the network, making it particularly dangerous for exposed systems.

What makes this vulnerability concerning is that an attacker only needs basic access credentials to exploit it.

This flaw poses a major risk to organizations using these systems for and monitoring.
Madison Drake · Thehackingpost

Someone with Observer role permissions, which are typically given to users who need to view system information, can use this flaw to elevate their privileges to Administrator level.

Once they gain administrator access, attackers can create new user accounts, modify system settings, and perform other unauthorized actions that compromise the security of the entire network infrastructure.

Cisco security researchers identified this vulnerability during work on a support case with the Technical Assistance Center.

The company has confirmed that no public exploits have been observed yet, which gives organizations a window to patch their systems before widespread attacks begin.

The vulnerability affects Cisco Catalyst Center Virtual Appliance versions 2.3.7.3-VA and later releases.

The security flaw is rooted in insufficient validation mechanisms that process user-supplied input through HTTP requests.

Advertisement

When the system receives these crafted requests, it fails to properly sanitize the data before processing privilege escalation operations.

Cisco has released version 2.3.7.10-VA as the fixed release that addresses this security issue. Organizations running affected versions should upgrade immediately to this patched version.

CVE IDCVSS ScoreAffected ProductVulnerable VersionsFixed VersionAttack VectorCVE-2025-203418.8 (High)Cisco Catalyst Center Virtual Appliance (VMware ESXi)2.3.7.3-VA and later2.3.7.10-VANetwork (Remote) The company has stated that no workarounds are available, making the software update the only effective way to protect against this vulnerability.

Hardware appliances and AWS-based virtual appliances are not affected by this issue.

Follow us on  Google News ,  LinkedIn , and  X  to Get More Instant Updates ,  Set CSN as a Preferred Source in  Google .

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories