Impact
An unauthenticated network attacker can send a crafted HTTP request to a Cisco Catalyst Center device, exploiting insufficient input validation to read an arbitrary file from a restricted container. This path‑traversal style weakness (CWE‑22) allows disclosure of confidential configuration or system data, resulting in a Remote File Read.
Affected Systems
All released versions of Cisco Catalyst Center are potentially vulnerable. The advisory identifies insufficient validation of user‑supplied input as the root cause, and no specific version ranges are excluded.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, while the EPSS score of less than 1 % suggests a low current probability of exploitation. The vulnerability is not listed in CISA's KEV catalog. An attacker would need unauthenticated network access to the device’s management interface via HTTP traffic to send the crafted request.
OpenCVE Enrichment