CVE 5.8 MEDIUM

Cisco SD-WAN vEdge Software Access Control List Bypass Vulnerability_CVE-2025-20339

5.8 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N

Description

A vulnerability in the access control list (ACL) processing of IPv4 packets of Cisco SD-WAN vEdge Software could allow an unauthenticated, remote attacker to bypass a configured ACL.

This vulnerability is due to the improper enforcement of the implicit deny all at the end of a configured ACL. An attacker could exploit this vulnerability by attempting to send unauthorized traffic to an interface on an affected device. A successful exploit could allow the attacker to bypass an ACL on the affected device.

Basic Information

ID CVE-2025-20339
Source cisco
Published Sep 24, 2025 at 16:40
Modified Sep 24, 2025 at 17:04

Affected Product

Vendor Cisco
Product Cisco SD-WAN vEdge Cloud
Version 20.9.1
Affected Versions Cisco Cisco SD-WAN vEdge Cloud 20.9.1
Cisco Cisco SD-WAN vEdge Cloud 20.9.1.1
Cisco Cisco SD-WAN vEdge Cloud 20.9.2
Cisco Cisco SD-WAN vEdge Cloud 20.9.3
Cisco Cisco SD-WAN vEdge Cloud 20.9.3.1
Cisco Cisco SD-WAN vEdge Cloud 20.9.2.2
Cisco Cisco SD-WAN vEdge Cloud 20.9.2.3
Cisco Cisco SD-WAN vEdge Cloud 20.9.4
Cisco Cisco SD-WAN vEdge Cloud 20.9.5
Cisco Cisco SD-WAN vEdge Cloud 20.9.5.1
Cisco Cisco SD-WAN vEdge Cloud 20.9.6
Cisco Cisco SD-WAN vEdge Cloud 20.9.5.3
Cisco Cisco SD-WAN vEdge Router 20.3.1
Cisco Cisco SD-WAN vEdge Router 20.3.2
Cisco Cisco SD-WAN vEdge Router 20.4.1
Cisco Cisco SD-WAN vEdge Router 20.4.1.1
Cisco Cisco SD-WAN vEdge Router 20.3.3
Cisco Cisco SD-WAN vEdge Router 20.4.1.2
Cisco Cisco SD-WAN vEdge Router 20.4.2
Cisco Cisco SD-WAN vEdge Router 20.3.4
Cisco Cisco SD-WAN vEdge Router 20.3.5
Cisco Cisco SD-WAN vEdge Router 20.9.1
Cisco Cisco SD-WAN vEdge Router 20.3.6
Cisco Cisco SD-WAN vEdge Router 20.9.2
Cisco Cisco SD-WAN vEdge Router 20.3.7
Cisco Cisco SD-WAN vEdge Router 20.9.3
Cisco Cisco SD-WAN vEdge Router 20.3.3.2
Cisco Cisco SD-WAN vEdge Router 20.3.4.3
Cisco Cisco SD-WAN vEdge Router 20.9.3.1
Cisco Cisco SD-WAN vEdge Router 20.3.7.1
Cisco Cisco SD-WAN vEdge Router 20.3.5.1
Cisco Cisco SD-WAN vEdge Router 20.4.2.3
Cisco Cisco SD-WAN vEdge Router 20.9.2.2
Cisco Cisco SD-WAN vEdge Router 20.3.7.2
Cisco Cisco SD-WAN vEdge Router 20.9.2.3
Cisco Cisco SD-WAN vEdge Router 20.9.4
Cisco Cisco SD-WAN vEdge Router 20.12.1
Cisco Cisco SD-WAN vEdge Router 20.3.8
Cisco Cisco SD-WAN vEdge Router 20.9.4.1777
Cisco Cisco SD-WAN vEdge Router 20.9.5
Cisco Cisco SD-WAN vEdge Router 20.9.5.1
Cisco Cisco SD-WAN vEdge Router 20.12.3.1
Cisco Cisco SD-WAN vEdge Router 20.9.6
Cisco Cisco SD-WAN vEdge Router 20.9.5.3

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.