Denial of Service Vulnerability in Cisco IOS XE Software's SNMP Subsystem
CVE-2025-20312

7.7HIGH

Key Information:

Vendor

Cisco

Vendor
CVE Published:
24 September 2025

Badges

👾 Exploit Exists

What is CVE-2025-20312?

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability arises from improper error handling while parsing specific SNMP requests. An attacker could exploit this by sending a specially crafted SNMP request, potentially leading to an unexpected device reload and subsequent denial of service. It is critical to note that exploiting this vulnerability requires knowledge of valid SNMP community strings for versions 1 and 2c, or valid user credentials for SNMP version 3.

Affected Version(s)

Cisco IOS XE Software 17.2.1

Cisco IOS XE Software 17.2.1r

Cisco IOS XE Software 17.2.1a

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20312 : Denial of Service Vulnerability in Cisco IOS XE Software's SNMP Subsystem