Denial of Service Vulnerability in Cisco Catalyst 9000 Series Switches
CVE-2025-20311
7.4HIGH
What is CVE-2025-20311?
A vulnerability exists in the handling of specific Ethernet frames within Cisco IOS XE Software for the Catalyst 9000 Series Switches, which permits unauthenticated, adjacent attackers to block egress ports and disrupt normal outbound traffic. This flaw stems from improper processing of crafted Ethernet frames. By sending specially crafted Ethernet frames to the affected switch, an attacker can exploit this vulnerability, leading to all frames being dropped from the affected egress port. This situation can result in a significant denial of service (DoS) condition for devices relying on that port for connectivity.
Affected Version(s)
Cisco IOS XE Software 16.6.1
Cisco IOS XE Software 16.6.2
Cisco IOS XE Software 16.6.3