DoS Vulnerability in Cisco IOS Software's SNMP Subsystem
CVE-2025-20173

7.7HIGH

Key Information:

Vendor
Cisco
Vendor
CVE Published:
5 February 2025

Badges

👾 Exploit Exists

Summary

A vulnerability in the SNMP subsystem of Cisco IOS and IOS XE Software may allow an authenticated remote attacker to trigger a denial of service condition. This issue arises from improper error management when processing SNMP requests. An attacker can exploit this flaw by dispatching a specially crafted SNMP request to a vulnerable device, which can lead to an unexpected device reload and subsequent service interruption. Affected SNMP protocols include versions 1, 2c, and 3. For SNMP v2c or earlier exploitation, knowledge of a valid community string is required. For SNMP v3, valid user credentials are necessary for access.

Affected Version(s)

Cisco IOS XE Software 3.2.0SG

Cisco IOS XE Software 3.2.1SG

Cisco IOS XE Software 3.2.2SG

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.