CVE-2025-20169
A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. This vulnerabilit
Description
A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition. This vulnerability affects SNMP versions 1, 2c, and 3. To exploit this vulnerability through SNMP v2c or earlier, the attacker must know a valid read-write or read-only SNMP community string for the affected system. To exploit this vulnerability through SNMP v3, the attacker must have valid SNMP user credentials for the affected system.
Weakness: CWE-805
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | Cisco IOS Software | Routing & Switching | cna-assigner |
| Cisco | Cisco IOS XE Software | Routing & Switching | cna-assigner |
Vendor-reported products (2)
- Cisco · IOS
- Cisco · Cisco IOS XE Software
Vendor advisory
Cisco IOS, IOS XE, and IOS XR Software SNMP Denial of Service Vulnerabilities
Cisco’s rating: High (advisory CVSS 7.7) · Published Feb 5, 2025 · updated Mar 12, 2025 (revision 1.1)
Bug IDs: CSCwm79554 , CSCwm79564 , CSCwm79570 , CSCwm79577 , CSCwm79581 , CSCwm79590 , CSCwm79596 , CSCwm89600 , CSCwn08493
The vendor’s rating applies to the whole advisory and can differ from this CVE’s own CVSS severity. Where this comes from