CVE-2025-20119 - CVE House
Back to Database
Status published Medium CVE-2025-20119

Cisco Application Policy Infrastructure Controller Authenticated Local Denial of Service Vulnerability

Vulnerability Description

A vulnerability in the system file permission handling of Cisco APIC could allow an authenticated, local attacker to overwrite critical system files, which could cause a DoS condition. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to a race condition with handling system files. An attacker could exploit this vulnerability by doing specific operations on the file system. A successful exploit could allow the attacker to overwrite system files, which could lead to the device being in an inconsistent state and cause a DoS condition.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-20119

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Cisco Application Policy Infrastructure Controller (APIC)
Vulnerable Versions:
3.2(8d), 3.2(1m), 3.2(5e), 4.1(2m), 3.2(41d), 3.2(3s), 4.0(3c), 4.1(1k), 3.2(4d), 4.2(2e), 4.2(3j), 4.2(3n), 4.0(1h), 4.1(1l), 3.2(9f), 4.2(3l), 4.2(2g), 3.2(7k), 3.2(9b), 3.2(3j), 4.1(2u), 4.2(1l), 4.1(1a), 4.0(3d), 3.2(4e), 4.1(1i), 3.2(5f), 3.2(1l), 4.2(1i), 4.1(2o), 4.2(1g), 4.1(2g), 4.2(2f), 3.2(6i), 3.2(3i), 3.2(3n), 4.1(2x), 3.2(5d), 4.2(3q), 4.1(1j), 4.1(2w), 3.2(2o), 3.2(3r), 4.0(2c), 4.1(2s), 3.2(7f), 3.2(3o), 3.2(2l), 4.2(1j), 4.2(4i), 3.2(9h), 5.0(1k), 4.2(4k), 5.0(1l), 5.0(2e), 4.2(4o), 4.2(4p), 5.0(2h), 4.2(5k), 4.2(5l), 4.2(5n), 5.1(1h), 4.2(6d), 5.1(2e), 4.2(6g), 4.2(6h), 5.1(3e), 3.2(10e), 4.2(6l), 4.2(7f), 5.1(4c), 4.2(6o), 5.2(1g), 5.2(2e), 4.2(7l), 3.2(10f), 5.2(2f), 5.2(2g), 4.2(7q), 5.2(2h), 5.2(3f), 5.2(3e), 5.2(3g), 4.2(7r), 4.2(7s), 5.2(4d), 5.2(4e), 4.2(7t), 5.2(5d), 3.2(10g), 5.2(5c), 6.0(1g), 4.2(7u), 5.2(5e), 5.2(4f), 5.2(6e), 6.0(1j), 5.2(6g), 5.2(7f), 4.2(7v), 5.2(7g), 6.0(2h), 4.2(7w), 5.2(6h), 5.2(4h), 5.2(8d), 6.0(2j), 5.2(8e), 6.0(3d), 6.0(3e), 5.2(8f), 5.2(8g), 5.3(1d), 5.2(8h), 6.0(4c), 5.3(2a), 5.2(8i), 6.0(5h), 5.3(2b), 6.0(3g), 6.0(5j), 5.3(2c), 6.0(6c), 6.1(1f), 6.0(7e), 5.3(2d), 6.0(8d), 5.3(2e)

Timeline

Official Publish: February 26th, 2025
Last Modified: March 3rd, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H

Weaknesses (CWE)