02 Records
FEED: ACQUIRING
01 RecordSTATE: PUBLISHED
02 Description
CNA: ciscoCisco Catalyst Center Privilege Escalation Vulnerability
03 Exploitation and scoring
SRC: CISA, FIRST, NVD, RED HAT- Exploitation
- Assessed, none found. CISA's assessment recorded neither public exploit code nor evidence of exploitation when it was made.
- SSVC decision
- ExploitationnoneCISA recorded no public exploit code and no evidence of exploitation.
- AutomatablenoAt least one step from reconnaissance to exploitation cannot be reliably automated.
- Technical ImpacttotalSuccessful exploitation gives total control of the vulnerable component.
CISA publishes the decision points, not a final SSVC decision. The decision also depends on mission and well-being impact, which is a property of your deployment rather than of the vulnerability.- EPSS probability
- 0.27% probability of exploitation activity in the next 30 days.
- EPSS percentile
- Ranks above 18.9% of scored records. A rank, not a probability.
- NVD base score
- 4.3 (CVSS v3.x), scored by the NVD independently of the CNA.
- NVD CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- NVD analysis status
- Analyzed. NVD last modified this record on 2026-06-17.
- Red Hat severity
- No Red Hat rating. Red Hat rates the CVEs that affect its products.
Exploit-prediction scores from FIRST. Independent scoring and analysis status from the NVD. Vendor severity from Red Hat. Exploitation assessment and catalog membership from CISA.
SCHEMA: 5.2
- Published
- 2025-11-13 16:27Z9 MO AGO
- Last updated
- 2026-02-26 16:57Z6 MO AGO
- Reserved
- 2024-10-10
- Assigning CNA
- cisco
- Record state
- PUBLISHED
- Severity
- Medium (CVSS 4.3)
- CNA CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- Weaknesses
- CWE-269Improper Privilege ManagementClass
- Data version
- 5.2
- Document digest
- 6e713e4ee426f4931511a92d7e42d58f252f3e6732a77e7446ec37998fe3a194
05 Affected products
PAIRS: 1VendorProductVersionsPlatforms
CiscoCisco Digital Network Architecture Center (DNA Center)2.1.1.0, 2.1.1.3, 2.1.2.0, 2.1.2.3, 2.1.2.5, 2.2.1.0, 2.1.2.6, 2.2.2.0, 2.2.2.3, 2.1.2.7, 2.2.1.3, 2.2.3.0, 2.2.2.4, 2.2.2.5, 2.2.3.3, 2.2.2.7, 2.2.2.6, 2.2.2.8, 2.2.3.4, 2.3.2.1, 2.3.2.1-AIRGAP, 2.3.2.1-AIRGAP-CA, 2.2.3.5, 2.3.3.3, 2.3.3.1-AIRGAP, 2.3.3.1, 2.3.2.3, 2.3.3.3-AIRGAP, 2.2.2.9, 2.3.3.0-AIRGAP, 2.3.3.4, 2.3.3.4-AIRGAP, 2.3.3.4-AIRGAP-MDNAC, 2.3.3.5, 2.3.3.5-AIRGAP, 2.3.4.0-AIRGAP, 2.3.4.3, 2.3.4.3-AIRGAP, 2.3.3.6, 2.3.3.6-AIRGAP, 2.3.3.6-AIRGAP-MDNAC, 2.3.5.0-AIRGAP-MDNAC, VA Launchpad 1.0.3, VA Launchpad 1.0.4, 2.3.3.7, 2.3.3.7-AIRGAP, 2.3.3.7-AIRGAP-MDNAC, 2.3.6.0, 2.3.3.6-70045-HF1, VA Launchpad 1.2.1, 2.3.3.7-72328-AIRGAP, 2.3.3.7-72323, 2.3.3.7-72328-MDNAC, 2.3.5.3, 2.3.5.3-AIRGAP-MDNAC, 2.3.5.3-AIRGAP, 2.3.6.0-AIRGAP, VA Launchpad 1.3.0, VA Launchpad 1.5.0, 2.3.7.0, 2.3.7.0-AIRGAP, 2.3.7.0-AIRGAP-MDNAC, 2.3.7.0-VA, 2.3.5.4-AIRGAP, 2.3.5.4-AIRGAP-MDNAC, VA Launchpad 1.6.0, 2.3.7.3, 2.3.7.3-AIRGAP, 2.3.7.3-AIRGAP-MDNAC, VA Launchpad 1.7.0, 2.3.5.5-AIRGAP, 2.3.5.5, 2.3.5.5-AIRGAP-MDNAC, 2.3.7.4, 2.3.7.4-AIRGAP, 2.3.7.5-AIRGAP, VA Launchpad 1.9.0, 2.3.5.6-AIRGAP, 2.3.5.6-AIRGAP-MDNAC, 1.0.0.0, Cisco CCGM 1.0.0.0, 2.3.7.6-AIRGAP, 2.3.7.6, 2.3.7.6-VA, 2.3.5.5-70026-HF70, 2.3.5.5-70026-HF51, 2.3.5.6-70143-HF20, 2.3.7.6-AIRGAP-MDNAC, 2.3.5.5-70026-HF53, 2.3.5.5-70026-HF71, 2.3.7.7, 2.3.7.7-VA, 2.3.7.7-AIRGAP, 2.3.7.7-AIRGAP-MDNAC, 2.3.7.9-VA, 2.3.7.9, 2.3.7.9-AIRGAP, 2.3.7.9-AIRGAP-MDNAC, Cisco CCGM 1.1.1, 2.3.7.9-70301-GSMU10, 2.3.7.9-70301-SMU1, 2.3.7.9-75403-SMU10, 2.3.7.9-75403-GSMU10, Cisco CCGM 1.2.1, 2.3.5.3-EULA, 2.3.7.9.75403.10-VA, 0.0.0.0, 1.16.54—