Cisco IOS XE Software Vulnerability Allows Persistent Code Execution
CVE-2025-20314

6.7MEDIUM

Key Information:

Vendor

Cisco

Vendor
CVE Published:
24 September 2025

Badges

👾 Exploit Exists

What is CVE-2025-20314?

A vulnerability in Cisco IOS XE Software allows an attacker with level-15 privileges or an unauthorized individual with physical access to an affected device to execute persistent code at boot time, undermining device security. This flaw stems from inadequate validation of software packages, enabling an attacker to place a specially crafted file in a designated location on the device. Successful exploitation of this vulnerability could lead to an attacker overriding the device's standard security mechanisms, resulting in a breach of the chain of trust, which is essential for ensuring the integrity of the operating system.

Affected Version(s)

Cisco IOS XE Software 17.3.1

Cisco IOS XE Software 17.3.2

Cisco IOS XE Software 17.3.3

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20314 : Cisco IOS XE Software Vulnerability Allows Persistent Code Execution