CVE-2025-20156

Published Jan 22, 2025

Last updated 7 days ago

Overview

Description
A vulnerability in the REST API of Cisco Meeting Management could allow a remote, authenticated attacker with low privileges to elevate privileges to administrator on an affected device. This vulnerability exists because proper authorization is not enforced upon REST API users. An attacker could exploit this vulnerability by sending API requests to a specific endpoint. A successful exploit could allow the attacker to gain administrator-level control over edge nodes that are managed by Cisco Meeting Management.
Source
psirt@cisco.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.9
Impact score
6
Exploitability score
3.1
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

psirt@cisco.com
CWE-274

Social media

Hype score
Not currently trending
  1. آسیب پذیری جدیدی برای Management REST API مربوط به Cisco با کد شناسایی CVE-2025-20156 منتشر شده است. این آسیب پذیری باعث می شود که هکر با سطح دسترسی پایین به سطح دسترسی admibistrator ارتقا پیدا نماید. نمره این آسیب پذیزی 9.9 می باشد. https://t.co/Poz3aKY03t https://t.co/kr4KYgHU

    @AmirHossein_sec

    30 Jan 2025

    23 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. سیسکو یک Patch برای رفع آسیب‌پذیری CVE-2025-20156 در Cisco Meeting Management منتشر کرده است.این مشکل، ناشی از عدم احراز هویت صحیح در REST API است و می‌تواند به مهاجمان اجازه دهد سطح دسترسی خود را به ادمین ارتقا دهند. این آسیب‌پذیری امتیاز 9.9 در CVSS دارد. منبع : Dark Reading h

    @techbox_ir

    29 Jan 2025

    22 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Cisco has fixed a critical security flaw in Meeting Management software, CVE-2025-20156. Update now! https://t.co/7xmuL8SO0b

    @threatlight

    27 Jan 2025

    16 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Top 5 Trending CVEs: 1 - CVE-2024-49138 2 - CVE-2024-43468 3 - CVE-2024-50050 4 - CVE-2025-20156 5 - CVE-2020-11023 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    26 Jan 2025

    167 Impressions

    1 Retweet

    3 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  5. 2/8 CVE-2025-20156 in @Cisco Meeting Management: Critical vulnerability allows privilege escalation. Upgrade to version 3.9.1 as soon as possible to secure your network. #CyberSecurity #CiscoUpdate 🚨 @CiscoNetworking @Ciscocola

    @Eth1calHackrZ

    26 Jan 2025

    13 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Cisco has released a critical patch for CVE-2025-20156, allowing remote attackers admin access via the Meeting Management REST API. Users should upgrade from version 3.9 or earlier. 🔒🇺🇸 #CiscoPatch #Vulnerability #RemoteAccess link: https://t.co/ZDfOnz7BuF https://t.co/QD7cFO

    @TweetThreatNews

    24 Jan 2025

    29 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. Vulnerabilidad crítica en Cisco Meeting Management CVE-2025-20156 Gravedad 9.9 sobre 10 https://t.co/K19PPGyeQH

    @elhackernet

    24 Jan 2025

    2527 Impressions

    11 Retweets

    42 Likes

    5 Bookmarks

    0 Replies

    0 Quotes

  8. 🚨 Weekly Cyber Roundup - New Threats to Watch Out For 🚨 Hey, CyberSentinels! Here's what's been happening in the cybersecurity landscape this week: 🔐Critical Cisco Flaw Exposes Admin Access: A new vulnerability in Cisco Meeting Management, identified as CVE-2025-20156, has…

    @EncryptSentinel

    23 Jan 2025

    34 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. Cisco Meeting Management REST API Privilege Escalation Vulnerability (CVE-2025-20156) #API #Cisco #CiscoMeetingManagement #CVE202520156 #CyberSecurity #PrivilegeEscalationVulnerability https://t.co/xeGn0qpca6

    @SystemTek_UK

    23 Jan 2025

    13 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. CVE-2025-20156 impacts Cisco Meeting Management #CVE-2025-20156 #Cisco https://t.co/1KCzQ7XFxu

    @pravin_karthik

    23 Jan 2025

    46 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  11. Cisco has patched critical vulnerabilities, including CVE-2025-20156 in Meeting Management, allowing remote privilege escalation. Users should update systems to prevent attacks. 🚨 #Cisco #US #VulnerabilityPatch link: https://t.co/Ls24SFsHMq https://t.co/hrKHDuwWGU

    @TweetThreatNews

    23 Jan 2025

    48 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  12. #Cisco released Security Updates to address Critical Privilege Escalation Vulnerability in Cisco Meeting Management REST API. Apply Updates! #CVE-2025-20156 https://t.co/3pIurljBCR

    @NCIIPC

    23 Jan 2025

    23 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. CVE-2025-20156 alert 🚨 Cisco: Privilege escalation in Meeting Management The vulnerability has been integrated into Patrowl. Our customers assets are protected. 🦉 #CyberSecurity #InfoSec #cisco https://t.co/8UvUePdFMN

    @Patrowl_io

    23 Jan 2025

    41 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. Cisco addresses a critical privilege escalation flaw (CVE-2025-20156) in Meeting Management, scoring 9.9. Updates also fix DoS vulnerabilities in BroadWorks and ClamAV. ⚠️ #Cisco #CyberThreats #USA link: https://t.co/vIUFsbsMAQ https://t.co/ZtqZrZa6mk

    @TweetThreatNews

    23 Jan 2025

    36 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. Cisco’s Double Whammy: Meeting Management Flaw and BroadWorks Bug – Patch Now! Hot Take: Oh Cisco, you’ve done it again! Just when we thought our network equipment could get a breather, the cyber world drops another bombshell. With CVE-2025-20156 threatening administrator… http

    @TheNimbleNerd

    23 Jan 2025

    41 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. 🚨 Critical Cisco Flaw Exposes Admin Access! A new vulnerability in Cisco Meeting Management (CVE-2025-20156) could allow attackers to gain full administrator control. Learn more: https://t.co/M9p0ELRzjM

    @TheHackersNews

    23 Jan 2025

    11287 Impressions

    54 Retweets

    95 Likes

    14 Bookmarks

    3 Replies

    4 Quotes

  17. Cisco Meeting ManagementのREST APIで、適切な認可チェックが行われていないため、攻撃者はREST APIエンドポイントに特定のリクエストを送信することで、管理者権限を持つデバイスを制御できる脆弱性 CVE-2025-20156 CVSS9.9 対策:バージョン3.9の製品は3.9.1にアップデートすることで問題を解消 https://t.co/RTf0YsZAGJ

    @t_nihonmatsu

    23 Jan 2025

    359 Impressions

    0 Retweets

    4 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  18. CVE-2025-20156 (CVSS 9.9): Cisco Meeting Management Flaw Allows for Privilege Escalation https://t.co/Rgi9wNkSpL

    @Dinosn

    23 Jan 2025

    2240 Impressions

    7 Retweets

    16 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  19. [CVE-2025-20156: CRITICAL] Vulnerability in Cisco Meeting Management's REST API allows attackers to gain admin privileges on affected devices by exploiting improper authorization enforcement.#cybersecurity,#vulnerability https://t.co/jh9a7SGZmU https://t.co/zRE23kgQ7W

    @CveFindCom

    22 Jan 2025

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes