CVE-2025-20119
Last modified
CVE-2025-20119 is a medium-severity vulnerability rated 5.7/10 on the CVSS scale. A vulnerability in the system file permission handling of Cisco APIC could allow an authenticated, local attacker to overwrite critical system files, which could cause a DoS condition. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to a race condition with handling system files. EPSS estimates a 0.09% chance of exploitation in the next 30 days.
Description
A vulnerability in the system file permission handling of Cisco APIC could allow an authenticated, local attacker to overwrite critical system files, which could cause a DoS condition. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to a race condition with handling system files. An attacker could exploit this vulnerability by doing specific operations on the file system. A successful exploit could allow the attacker to overwrite system files, which could lead to the device being in an inconsistent state and cause a DoS condition.
Metrics
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Application Policy Infrastructure Controller | 3.2\(1l\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(1m\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(2l\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(2o\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(3i\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(3j\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(3n\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(3o\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(3r\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(3s\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(4d\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(4e\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(5d\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(5e\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(5f\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(6i\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(7f\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(7k\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(8d\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(9b\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(9f\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(9h\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(10e\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(10f\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(10g\) |
| Cisco | Application Policy Infrastructure Controller | 3.2\(41d\) |
| Cisco | Application Policy Infrastructure Controller | 4.0\(1h\) |
| Cisco | Application Policy Infrastructure Controller | 4.0\(2c\) |
| Cisco | Application Policy Infrastructure Controller | 4.0\(3c\) |
| Cisco | Application Policy Infrastructure Controller | 4.0\(3d\) |
| Cisco | Application Policy Infrastructure Controller | 4.1\(1a\) |
| Cisco | Application Policy Infrastructure Controller | 4.1\(1i\) |
| Cisco | Application Policy Infrastructure Controller | 4.1\(1j\) |
| Cisco | Application Policy Infrastructure Controller | 4.1\(1k\) |
| Cisco | Application Policy Infrastructure Controller | 4.1\(1l\) |
| Cisco | Application Policy Infrastructure Controller | 4.1\(2g\) |
| Cisco | Application Policy Infrastructure Controller | 4.1\(2m\) |
| Cisco | Application Policy Infrastructure Controller | 4.1\(2o\) |
| Cisco | Application Policy Infrastructure Controller | 4.1\(2s\) |
| Cisco | Application Policy Infrastructure Controller | 4.1\(2u\) |
| Cisco | Application Policy Infrastructure Controller | 4.1\(2w\) |
| Cisco | Application Policy Infrastructure Controller | 4.1\(2x\) |
| Cisco | Application Policy Infrastructure Controller | 4.2\(1g\) |
| Cisco | Application Policy Infrastructure Controller | 4.2\(1i\) |
| Cisco | Application Policy Infrastructure Controller | 4.2\(1j\) |
| Cisco | Application Policy Infrastructure Controller | 4.2\(1l\) |
| Cisco | Application Policy Infrastructure Controller | 4.2\(2e\) |
| Cisco | Application Policy Infrastructure Controller | 4.2\(2f\) |
| Cisco | Application Policy Infrastructure Controller | 4.2\(2g\) |
| Cisco | Application Policy Infrastructure Controller | 4.2\(3j\) |
Showing 50 of 128 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-20119?
How severe is CVE-2025-20119?
How do I fix CVE-2025-20119?
Are you affected by CVE-2025-20119?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
