Path Traversal and Integrity Validation Issues in Cisco IOS XE Software
CVE-2025-20313

6.7MEDIUM

Key Information:

Vendor

Cisco

Vendor
CVE Published:
24 September 2025

Badges

👾 Exploit Exists

What is CVE-2025-20313?

Cisco IOS XE Software is susceptible to multiple vulnerabilities that could enable an attacker with high-level access or physical access to execute persistent code upon system boot. These vulnerabilities stem from flaws related to path traversal and inadequate image integrity validation. Exploiting these issues could allow an attacker to bypass significant security measures, compromising the integrity of the operating system. Organizations using affected versions should review the advisory for crucial details and implement necessary security measures.

Affected Version(s)

Cisco IOS XE Software 17.3.1

Cisco IOS XE Software 17.3.2

Cisco IOS XE Software 17.3.3

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20313 : Path Traversal and Integrity Validation Issues in Cisco IOS XE Software