CVE-2025-20173
CVSS 3.1 Score 7.7 of 10 (high)
Details
Summary
CVE-2025-20173 is a vulnerability impacting the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software. It allows authenticated, remote attackers to trigger a Denial of Service (DoS) condition on affected devices. The cause of this vulnerability is improper error handling during SNMP request parsing. An attacker can exploit this flaw by sending specially crafted SNMP requests to the device. In the case of SNMP v2c and earlier, the attacker requires a valid read-write or read-only community string. For SNMP v3, a successful attack necessitates valid SNMP user credentials. A successful exploit can lead to an unexpected device reload, resulting in the DoS condition.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.