CISCO-SA-DNAC-API-NBPZCJCM
A vulnerability in the management API of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an unauthenticated, remote attacker to read and modify the outgoing proxy configuration settings. This vulnerability is due to the lack of authentication in an API endpoint. An attacker could exploit this vulnerability by sending a request to the affected API of a Catalyst Center device. A successful exploit could allow the attacker to view or modify the outgoing proxy configuration, which could disrupt internet traffic from Cisco Catalyst Center or may allow the attacker to intercept outbound internet traffic. Note: For information about Cisco Catalyst Center features that require an internet connection and the corresponding internet domains used, see the Required internet URLs and fully qualified domain names ["https://www.cisco.com/c/en/us/td/docs/cloud-systems-management/network-automation-and-management/catalyst-center/2-3-7/install_guide/b_cisco_catalyst_center_install_guide_237x_3rdgen/m_plan_deployment_2_x_x_3rdgen.html#concept_z4t_cd3_sfb"] section of the Cisco Catalyst Center Third-Generation Appliance Installation Guide. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco Digital Network Architecture Center (DNA Center) |
Timeline
- Mar 26, 2025 CVE Updated
- May 7, 2025 CVE Published
References
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-dnac-api-nBPZcJCM advisory
- https://sec.cloudapps.cisco.com/security/center/resources/security_vulnerability_policy.html url
- https://www.cisco.com/c/en/us/td/docs/cloud-systems-management/network-automation-and-management/catalyst-center/2-3-7/install_guide/b_cisco_catalyst_center_install_guide_237x_3rdgen/m_plan_deployment_2_x_x_3rdgen.html#concept_z4t_cd3_sfb url
- https://sec.cloudapps.cisco.com/security/center/resources/security_vulnerability_policy.html#ssu url
- https://www.cisco.com/c/en/us/products/end-user-license-agreement.html url
- https://www.cisco.com/c/en/us/support/index.html url
- https://sec.cloudapps.cisco.com/security/center/resources/security_vulnerability_policy.html#fixes url
- https://www.cisco.com/go/psirt url
- https://www.cisco.com/c/en/us/support/web/tsd-cisco-worldwide-contacts.html url
- http://www.cisco.com/web/about/security/psirt/security_vulnerability_policy.html url
- https://software.cisco.com fix