Arbitrary File Write Vulnerability in Cisco IOS XE Software
CVE-2025-20155
Summary
A vulnerability exists in the bootstrap loading process of Cisco IOS XE Software that permits an authenticated, local attacker to write arbitrary files to the affected system. This issue stems from insufficient input validation of the bootstrap file utilized during the initial deployment of devices in SD-WAN mode or when configuring SD-Routing. By manipulating the bootstrap file generated by Cisco Catalyst SD-WAN Manager and subsequently loading it onto the device, an attacker can exploit this vulnerability to execute unauthorized file writes to the device's operating system, posing significant risks to system integrity and security.
Affected Version(s)
Cisco IOS XE Software 17.9.4
Cisco IOS XE Software 17.9.5
Cisco IOS XE Software 17.9.4a
References
CVSS V3.1
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved