CVE-2025-20174

CVSS 3.1 Score 7.7 of 10 (high)

Details

Published Feb 5, 2025
CWE ID 805

Summary

CVE-2025-20174 is a vulnerability affecting the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software. It allows authenticated, remote attackers to cause a Denial of Service (DoS) condition on affected devices. This vulnerability arises from improper error handling while parsing SNMP requests. An attacker can exploit this vulnerability by sending a specially crafted SNMP request to the device. Depending on the SNMP version, the attacker may require valid community strings or user credentials to successfully trigger a reload, leading to the DoS condition. Versions 1, 2c, and 3 of SNMP are susceptible to this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share