Arbitrary File Write Vulnerability in Cisco IOS XE Software
CVE-2025-20155

6MEDIUM

Key Information:

Vendor
Cisco
Vendor
CVE Published:
7 May 2025

Badges

👾 Exploit Exists

Summary

A vulnerability exists in the bootstrap loading process of Cisco IOS XE Software that permits an authenticated, local attacker to write arbitrary files to the affected system. This issue stems from insufficient input validation of the bootstrap file utilized during the initial deployment of devices in SD-WAN mode or when configuring SD-Routing. By manipulating the bootstrap file generated by Cisco Catalyst SD-WAN Manager and subsequently loading it onto the device, an attacker can exploit this vulnerability to execute unauthorized file writes to the device's operating system, posing significant risks to system integrity and security.

Affected Version(s)

Cisco IOS XE Software 17.9.4

Cisco IOS XE Software 17.9.5

Cisco IOS XE Software 17.9.4a

References

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20155 : Arbitrary File Write Vulnerability in Cisco IOS XE Software | SecurityVulnerability.io