Description

A vulnerability in the REST API of Cisco Meeting Management could allow a remote, authenticated attacker with low privileges to elevate privileges to administrator on an affected device. This vulnerability exists because proper authorization is not enforced upon REST API users. An attacker could exploit this vulnerability by sending API requests to a specific endpoint. A successful exploit could allow the attacker to gain administrator-level control over edge nodes that are managed by Cisco Meeting Management.

INFO

Published Date :

2025-01-22T16:21:20.333Z

Last Modified :

2026-02-26T19:08:58.432Z

Source :

cisco
AFFECTED PRODUCTS

The following products are affected by CVE-2025-20156 vulnerability.

Vendors Products
Cisco
  • Meeting Management

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact