CVE-2025-20290
Last modified
CVE-2025-20290 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. A vulnerability in the logging feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches, Cisco Nexus 9000 Series Switches in standalone NX-OS mode, Cisco UCS 6400 Fabric Interconnects, Cisco UCS 6500 Series Fabric Interconnects, and Cisco UCS 9108 100G Fabric Interconnects could allow an authenticated, local attacker access to sensitive information. This vulnerability is due to improper logging of sensitive information. An attacker could exploit this vulnerability by accessing log files on the file system where they are stored. EPSS estimates a 0.13% chance of exploitation in the next 30 days.
Description
A vulnerability in the logging feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches, Cisco Nexus 9000 Series Switches in standalone NX-OS mode, Cisco UCS 6400 Fabric Interconnects, Cisco UCS 6500 Series Fabric Interconnects, and Cisco UCS 9108 100G Fabric Interconnects could allow an authenticated, local attacker access to sensitive information. This vulnerability is due to improper logging of sensitive information. An attacker could exploit this vulnerability by accessing log files on the file system where they are stored. A successful exploit could allow the attacker to access sensitive information, such as stored credentials.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-20290?
How severe is CVE-2025-20290?
How do I fix CVE-2025-20290?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-20285A vulnerability in the IP Access Restriction feature of Cisc…4.1
- CVE-2025-20286A vulnerability in Amazon Web Services (AWS), Microsoft Azur…9.8
- CVE-2025-20287A vulnerability in the web-based management interface of Cis…8.8
- CVE-2025-20288A vulnerability in the web-based management interface of Cis…5.3
- CVE-2025-20289Multiple vulnerabilities in the web-based management interfa…5.4
- CVE-2025-2029A vulnerability was found in MicroDicom DICOM Viewer 2025.1 …5.3
- CVE-2025-20291A vulnerability in Cisco Webex Meetings could have allowed a…6.1
- CVE-2025-20292A vulnerability in the CLI of Cisco NX-OS Software could all…4.4
- CVE-2025-20293A vulnerability in the Day One setup process of Cisco IOS XE…5.3
- CVE-2025-20294Multiple vulnerabilities in the CLI and web-based management…6.5
- CVE-2025-20295A vulnerability in the CLI of Cisco UCS Manager Software cou…6
- CVE-2025-20296A vulnerability in the web-based management interface of Cis…5.4
Are you affected by CVE-2025-20290?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
