CVE-2025-20294
Multiple vulnerabilities in the CLI and web-based management interface of Cisco UCS Manager Software could allow an authenticated, remote attacker with administrative privileges to perform command injection attacks on an affected system and elevate privileges to root. These vulnerabilities are due to insufficient input validation of command arguments supplied by the user. An attacker could exploit these vulnerabilities by authenticating to a device and submitting crafted input to the affected commands. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system of the affected device with root-level privileges.
EPSS 0.07% · 21.7th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Cisco Unified Computing System (Managed) | *, 4.0(1a), 4.1(1d) |
Exploit Intelligence
- CIRCL seen: CVE-2025-20294 (circl-sighting)
- CIRCL seen: CVE-2025-20294 (circl-sighting)
- CIRCL seen: CVE-2025-20294 (circl-sighting)
- CIRCL seen: CVE-2025-20294 (circl-sighting)
- cisco-sa-ucs-multi-cmdinj-E4Ukjyrz (circl)
Timeline
- Oct 10, 2024 CVE ID Reserved
- Aug 27, 2025 Coalition ESS Score
- Aug 27, 2025 CVE Published
- Aug 28, 2025 EPSS Score
- Sep 1, 2025 Coalition ESS Score
- Sep 2, 2025 PoC Published
- Sep 2, 2025 PoC Published
- Sep 2, 2025 PoC Published
- Sep 2, 2025 PoC Published
- Sep 5, 2025 EPSS Score
- Sep 13, 2025 EPSS Score
- Sep 20, 2025 EPSS Score