Denial of Service Vulnerability in Cisco Catalyst 9000 Series Switches
CVE-2025-20311

7.4HIGH

Key Information:

Vendor

Cisco

Vendor
CVE Published:
24 September 2025

Badges

👾 Exploit Exists

What is CVE-2025-20311?

A vulnerability exists in the handling of specific Ethernet frames within Cisco IOS XE Software for the Catalyst 9000 Series Switches, which permits unauthenticated, adjacent attackers to block egress ports and disrupt normal outbound traffic. This flaw stems from improper processing of crafted Ethernet frames. By sending specially crafted Ethernet frames to the affected switch, an attacker can exploit this vulnerability, leading to all frames being dropped from the affected egress port. This situation can result in a significant denial of service (DoS) condition for devices relying on that port for connectivity.

Affected Version(s)

Cisco IOS XE Software 16.6.1

Cisco IOS XE Software 16.6.2

Cisco IOS XE Software 16.6.3

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20311 : Denial of Service Vulnerability in Cisco Catalyst 9000 Series Switches