CVE-2025-20119
Last modified
CVE-2025-20119 is a medium-severity vulnerability rated 5.7/10 on the CVSS scale. A vulnerability in the system file permission handling of Cisco APIC could allow an authenticated, local attacker to overwrite critical system files, which could cause a DoS condition. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to a race condition with handling system files. EPSS estimates a 0.09% chance of exploitation in the next 30 days.
Description
A vulnerability in the system file permission handling of Cisco APIC could allow an authenticated, local attacker to overwrite critical system files, which could cause a DoS condition. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to a race condition with handling system files. An attacker could exploit this vulnerability by doing specific operations on the file system. A successful exploit could allow the attacker to overwrite system files, which could lead to the device being in an inconsistent state and cause a DoS condition.
Metrics
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Application Policy Infrastructure Controller | 3.2\(1l\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(1m\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(2l\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(2o\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(3i\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(3j\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(3n\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(3o\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(3r\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(3s\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(4d\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(4e\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(5d\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(5e\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(5f\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(6i\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(7f\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(7k\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(8d\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(9b\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(9f\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(9h\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(10e\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(10f\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(10g\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(41d\) |
| Cisco | Application Policy Infrastructure Controller | 4.0\(1h\) |
| Cisco | Application Policy Infrastructure Controller | 4.0\(2c\) |
| Cisco | Application Policy Infrastructure Controller | 4.0\(3c\) |
| Cisco | Application Policy Infrastructure Controller | 4.0\(3d\) |
| Cisco | Application Policy Infrastructure Controller | 4.1\(1a\) |
| Cisco | Application Policy Infrastructure Controller | 4.1\(1i\) |
| Cisco | Application Policy Infrastructure Controller | 4.1\(1j\) |
| Cisco | Application Policy Infrastructure Controller | 4.1\(1k\) |
| Cisco | Application Policy Infrastructure Controller | 4.1\(1l\) |
| Cisco | Application Policy Infrastructure Controller | 4.1\(2g\) |
| Cisco | Application Policy Infrastructure Controller | 4.1\(2m\) |
| Cisco | Application Policy Infrastructure Controller | 4.1\(2o\) |
| Cisco | Application Policy Infrastructure Controller | 4.1\(2s\) |
| Cisco | Application Policy Infrastructure Controller | 4.1\(2u\) |
| Cisco | Application Policy Infrastructure Controller | 4.1\(2w\) |
| Cisco | Application Policy Infrastructure Controller | 4.1\(2x\) |
| Cisco | Application Policy Infrastructure Controller | 4.2\(1g\) |
| Cisco | Application Policy Infrastructure Controller | 4.2\(1i\) |
| Cisco | Application Policy Infrastructure Controller | 4.2\(1j\) |
| Cisco | Application Policy Infrastructure Controller | 4.2\(1l\) |
| Cisco | Application Policy Infrastructure Controller | 4.2\(2e\) |
| Cisco | Application Policy Infrastructure Controller | 4.2\(2f\) |
| Cisco | Application Policy Infrastructure Controller | 4.2\(2g\) |
| Cisco | Application Policy Infrastructure Controller | 4.2\(3j\) |
Showing 50 of 128 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-20119?
How severe is CVE-2025-20119?
How do I fix CVE-2025-20119?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-20113A vulnerability in Cisco Unified Intelligence Center could a…7.1
- CVE-2025-20114A vulnerability in the API of Cisco Unified Intelligence Cen…4.3
- CVE-2025-20115A vulnerability in confederation implementation for the Bord…8.6
- CVE-2025-20116A vulnerability in the web UI of Cisco APIC could allow an a…4.8
- CVE-2025-20117A vulnerability in the CLI of Cisco APIC could allow an auth…6.7
- CVE-2025-20118A vulnerability in the implementation of the internal system…4.4
- CVE-2025-2012Ashlar-Vellum Cobalt VS File Parsing Out-Of-Bounds Read Remo…7.8
- CVE-2025-20120A vulnerability in the web-based management interface of Cis…6.1
- CVE-2025-20122A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager,…7.8
- CVE-2025-20123Multiple vulnerabilities in the web-based management interfa…4.8
- CVE-2025-20124A vulnerability in an API of Cisco ISE could allow an authen…7.2
- CVE-2025-20125A vulnerability in an API of Cisco ISE could allow an authen…7.2
Are you affected by CVE-2025-20119?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
