NewsSecurity Vulnerabilities

Cisco ThousandEyes Agent Certificate Validation Vulnerability (CVE-2025-20126)

CVE number CVE-2025-20126

A vulnerability in certification validation routines of Cisco ThousandEyes Endpoint Agent for macOS and RoomOS could allow an unauthenticated, remote attacker to intercept or manipulate metrics information.

This vulnerability exists because the affected software does not properly validate certificates for hosted metrics services. An on-path attacker could exploit this vulnerability by intercepting network traffic using a crafted certificate. A successful exploit could allow the attacker to masquerade as a trusted host and monitor or change communications between the remote metrics service and the vulnerable client.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

At the time of publication, this vulnerability affected Cisco ThousandEyes Endpoint agents for macOS and RoomOS if they were running a vulnerable release of Cisco ThousandEyes Endpoint Agent Software, regardless of device configuration.

Further information – https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-thousandeyes-cert-pqtJUv9N

Luke Simmonds

Blogger at www.systemtek.co.uk

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.