Impact
An unauthenticated attacker can send a crafted HTTP request to a Cisco Catalyst Center device, exploiting insufficient input validation to read an arbitrary file from a restricted container. This path‑traversal style weakness (CWE‑22) allows disclosure of confidential configuration or system data, resulting in a Remote File Read.
Affected Systems
All released versions of Cisco Catalyst Center are potentially vulnerable, as the advisory does not specify version ranges and identifies insufficient validation as the root cause.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, and the EPSS score of less than 1% suggests a low current probability of exploitation. The vulnerability is not listed in CISA's KEV catalog. An attacker would need unauthenticated network access to the device’s management interface, which is typical for remote HTTP traffic, to send the crafted request.
OpenCVE Enrichment