CVE-2025-20355: Cisco Digital Network Architecture Center Dna Center

Medium severity, CVSS 4.7. EPSS: 0.2% chance of exploitation in the next 30 days.

A vulnerability in the web-based management interface of Cisco Catalyst Center Virtual Appliance could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of HTTP request parameters. An attacker could exploit this vulnerability by intercepting and modifying an HTTP request from a user. A successful exploit could allow the attacker to redirect the user to a malicious web page.

Affected products

  • Cisco Cisco Digital Network Architecture Center Dna Center: version 1.4.0.0 only; version 2.1.1.0 only; version 2.1.1.3 only; version 2.1.2.0 only; version 2.1.2.3 only; version 2.1.2.4 only; …

Published 2025-11-13. Last modified 2026-10-07.