Local Privilege Escalation in Cisco IOS XE Software
CVE-2025-20197
What is CVE-2025-20197?
A local privilege escalation vulnerability exists in the CLI of Cisco IOS XE Software. Authenticated users with privilege level 15 can exploit this weakness, which stems from inadequate input validation when executing certain configuration commands. By providing malicious input, an attacker may gain root access to the device's operating system, potentially enabling them to carry out unauthorized actions without detection. It is crucial for administrators to be aware of this vulnerability and apply necessary mitigations, given that an attacker requires configuration mode access to exploit it.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cisco IOS XE Software 3.7.0S
Cisco IOS XE Software 3.7.1S
Cisco IOS XE Software 3.7.2S
References
CVSS V3.1
Timeline
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved