CVE-2025-20339: Cisco SD-WAN Vedge Cloud
Medium severity, CVSS 5.8. EPSS: 0.3% chance of exploitation in the next 30 days.
A vulnerability in the access control list (ACL) processing of IPv4 packets of Cisco SD-WAN vEdge Software could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to the improper enforcement of the implicit deny all at the end of a configured ACL. An attacker could exploit this vulnerability by attempting to send unauthorized traffic to an interface on an affected device. A successful exploit could allow the attacker to bypass an ACL on the affected device.
Affected products
- Cisco Cisco SD-WAN Vedge Cloud: version 20.9.1 only; version 20.9.1.1 only; version 20.9.2 only; version 20.9.3 only; version 20.9.3.1 only; version 20.9.2.2 only; …
- Cisco Cisco SD-WAN Vedge Router: version 20.3.1 only; version 20.3.2 only; version 20.4.1 only; version 20.4.1.1 only; version 20.3.3 only; version 20.4.1.2 only; …
Published 2025-09-24. Last modified 2026-09-26.