DoS Vulnerability in Cisco IOS Software and Cisco IOS XE Software SNMP Subsystem
CVE-2025-20170
7.7HIGH
Summary
A flaw in the SNMP subsystem of Cisco IOS and IOS XE Software can allow an authenticated remote attacker to trigger a Denial of Service condition. This occurs due to improper error handling during the parsing of SNMP requests. An attacker capable of sending a specially crafted SNMP request to an affected device may induce an unexpected reload of the system, rendering it inoperative. Exploitation via SNMP v2c or earlier requires knowledge of a valid SNMP community string, while exploitation through SNMP v3 necessitates valid SNMP user credentials.
Affected Version(s)
Cisco IOS XE Software 3.2.0SG
Cisco IOS XE Software 3.2.1SG
Cisco IOS XE Software 3.2.2SG
References
CVSS V3.1
Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved