6.5

CVE-2025-20190

A vulnerability in the lobby ambassador web interface of Cisco IOS XE Wireless Controller Software could allow an authenticated, remote attacker to remove arbitrary users that are defined on an affected device.

 This vulnerability is due to insufficient access control of actions executed by lobby ambassador users. An attacker could exploit this vulnerability by logging in to an affected device with a lobby ambassador user account and sending crafted HTTP requests to the API. A successful exploit could allow the attacker to delete arbitrary user accounts on the device, including users with administrative privileges.

 Note: This vulnerability is exploitable only if the attacker obtains the credentials for a lobby ambassador account. This account is not configured by default.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Data is provided by the National Vulnerability Database (NVD)
CiscoIos Xe Version17.6.8
   CiscoCatalyst 9800-cl Wireless Controllers For Cloud
   CiscoCatalyst 9105axi Version-
   CiscoCatalyst 9115axe Version-
   CiscoCatalyst 9115axi Version-
   CiscoCatalyst 9117axi Version-
   CiscoCatalyst 9120axe Version-
   CiscoCatalyst 9120axi Version-
   CiscoCatalyst 9120axp Version-
   CiscoCatalyst 9130axe Version-
   CiscoCatalyst 9130axi Version-
   CiscoCatalyst 9800-40 Version-
   CiscoCatalyst 9800-80 Version-
   CiscoCatalyst 9800-l Version-
   CiscoCatalyst Cw9800h1 Version-
   CiscoCatalyst Cw9800h2 Version-
   CiscoCatalyst Cw9800m Version-
CiscoIos Xe Version17.9.6
   CiscoCatalyst 9800-cl Wireless Controllers For Cloud
   CiscoCatalyst 9105axi Version-
   CiscoCatalyst 9115axe Version-
   CiscoCatalyst 9115axi Version-
   CiscoCatalyst 9117axi Version-
   CiscoCatalyst 9120axe Version-
   CiscoCatalyst 9120axi Version-
   CiscoCatalyst 9120axp Version-
   CiscoCatalyst 9130axe Version-
   CiscoCatalyst 9130axi Version-
   CiscoCatalyst 9800-40 Version-
   CiscoCatalyst 9800-80 Version-
   CiscoCatalyst 9800-l Version-
   CiscoCatalyst Cw9800h1 Version-
   CiscoCatalyst Cw9800h2 Version-
   CiscoCatalyst Cw9800m Version-
CiscoIos Xe Version17.9.6a
   CiscoCatalyst 9800-cl Wireless Controllers For Cloud
   CiscoCatalyst 9105axi Version-
   CiscoCatalyst 9115axe Version-
   CiscoCatalyst 9115axi Version-
   CiscoCatalyst 9117axi Version-
   CiscoCatalyst 9120axe Version-
   CiscoCatalyst 9120axi Version-
   CiscoCatalyst 9120axp Version-
   CiscoCatalyst 9130axe Version-
   CiscoCatalyst 9130axi Version-
   CiscoCatalyst 9800-40 Version-
   CiscoCatalyst 9800-80 Version-
   CiscoCatalyst 9800-l Version-
   CiscoCatalyst Cw9800h1 Version-
   CiscoCatalyst Cw9800h2 Version-
   CiscoCatalyst Cw9800m Version-
CiscoIos Xe Version17.12.1z2
   CiscoCatalyst 9800-cl Wireless Controllers For Cloud
   CiscoCatalyst 9105axi Version-
   CiscoCatalyst 9115axe Version-
   CiscoCatalyst 9115axi Version-
   CiscoCatalyst 9117axi Version-
   CiscoCatalyst 9120axe Version-
   CiscoCatalyst 9120axi Version-
   CiscoCatalyst 9120axp Version-
   CiscoCatalyst 9130axe Version-
   CiscoCatalyst 9130axi Version-
   CiscoCatalyst 9800-40 Version-
   CiscoCatalyst 9800-80 Version-
   CiscoCatalyst 9800-l Version-
   CiscoCatalyst Cw9800h1 Version-
   CiscoCatalyst Cw9800h2 Version-
   CiscoCatalyst Cw9800m Version-
CiscoIos Xe Version17.12.1z3
   CiscoCatalyst 9800-cl Wireless Controllers For Cloud
   CiscoCatalyst 9105axi Version-
   CiscoCatalyst 9115axe Version-
   CiscoCatalyst 9115axi Version-
   CiscoCatalyst 9117axi Version-
   CiscoCatalyst 9120axe Version-
   CiscoCatalyst 9120axi Version-
   CiscoCatalyst 9120axp Version-
   CiscoCatalyst 9130axe Version-
   CiscoCatalyst 9130axi Version-
   CiscoCatalyst 9800-40 Version-
   CiscoCatalyst 9800-80 Version-
   CiscoCatalyst 9800-l Version-
   CiscoCatalyst Cw9800h1 Version-
   CiscoCatalyst Cw9800h2 Version-
   CiscoCatalyst Cw9800m Version-
CiscoIos Xe Version17.15.1
   CiscoCatalyst 9800-cl Wireless Controllers For Cloud
   CiscoCatalyst 9105axi Version-
   CiscoCatalyst 9115axe Version-
   CiscoCatalyst 9115axi Version-
   CiscoCatalyst 9117axi Version-
   CiscoCatalyst 9120axe Version-
   CiscoCatalyst 9120axi Version-
   CiscoCatalyst 9120axp Version-
   CiscoCatalyst 9130axe Version-
   CiscoCatalyst 9130axi Version-
   CiscoCatalyst 9800-40 Version-
   CiscoCatalyst 9800-80 Version-
   CiscoCatalyst 9800-l Version-
   CiscoCatalyst Cw9800h1 Version-
   CiscoCatalyst Cw9800h2 Version-
   CiscoCatalyst Cw9800m Version-
CiscoIos Xe Version17.15.1x
   CiscoCatalyst 9800-cl Wireless Controllers For Cloud
   CiscoCatalyst 9105axi Version-
   CiscoCatalyst 9115axe Version-
   CiscoCatalyst 9115axi Version-
   CiscoCatalyst 9117axi Version-
   CiscoCatalyst 9120axe Version-
   CiscoCatalyst 9120axi Version-
   CiscoCatalyst 9120axp Version-
   CiscoCatalyst 9130axe Version-
   CiscoCatalyst 9130axi Version-
   CiscoCatalyst 9800-40 Version-
   CiscoCatalyst 9800-80 Version-
   CiscoCatalyst 9800-l Version-
   CiscoCatalyst Cw9800h1 Version-
   CiscoCatalyst Cw9800h2 Version-
   CiscoCatalyst Cw9800m Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.03% 0.079
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
psirt@cisco.com 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.