Description

A vulnerability in certification validation routines of Cisco ThousandEyes Endpoint Agent for macOS and RoomOS could allow an unauthenticated, remote attacker to intercept or manipulate metrics information. This vulnerability exists because the affected software does not properly validate certificates for hosted metrics services. An on-path attacker could exploit this vulnerability by intercepting network traffic using a crafted certificate. A successful exploit could allow the attacker to masquerade as a trusted host and monitor or change communications between the remote metrics service and the vulnerable client.

INFO

Published Date :

2025-01-08T16:09:46.465Z

Last Modified :

2025-01-13T22:24:43.145Z

Source :

cisco
AFFECTED PRODUCTS

The following products are affected by CVE-2025-20126 vulnerability.

Vendors Products
Apple
  • Macos
Cisco
  • Roomos
  • Thousandeyes Endpoint Agent
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-20126.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact