CVE-2025-20172
CVSS 3.1 Score 7.7 of 10 (high)
Details
Summary
CVE-2025-20172 is a vulnerability affecting Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software. It allows authenticated, remote attackers to induce a Denial of Service (DoS) condition on impacted devices. The root cause is improper error handling during SNMP request parsing. An adversary may exploit this by transmitting specially crafted SNMP requests. Depending on the software version, the attacker can trigger a device reload in Cisco IOS and IOS XE Software, leading to a DoS condition. In the case of Cisco IOS XR Software, the SNMP process will restart, disrupting SNMP responses from the affected device. SNMP versions 1, 2c, and 3 are all susceptible. To exploit versions 2c and earlier, an attacker needs a valid read-write or read-only community string. For SNMP v3, the adversary requires valid SNMP user credentials.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.