Local Privilege Escalation in Cisco IOS XE Software
CVE-2025-20197

6.7MEDIUM

Key Information:

Vendor
Cisco
Vendor
CVE Published:
7 May 2025

Badges

👾 Exploit Exists

Summary

A local privilege escalation vulnerability exists in the CLI of Cisco IOS XE Software. Authenticated users with privilege level 15 can exploit this weakness, which stems from inadequate input validation when executing certain configuration commands. By providing malicious input, an attacker may gain root access to the device's operating system, potentially enabling them to carry out unauthorized actions without detection. It is crucial for administrators to be aware of this vulnerability and apply necessary mitigations, given that an attacker requires configuration mode access to exploit it.

Affected Version(s)

Cisco IOS XE Software 3.7.0S

Cisco IOS XE Software 3.7.1S

Cisco IOS XE Software 3.7.2S

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20197 : Local Privilege Escalation in Cisco IOS XE Software | SecurityVulnerability.io