Cisco IOS XE Software Vulnerability Allows Persistent Code Execution
CVE-2025-20314
6.7MEDIUM
What is CVE-2025-20314?
A vulnerability in Cisco IOS XE Software allows an attacker with level-15 privileges or an unauthorized individual with physical access to an affected device to execute persistent code at boot time, undermining device security. This flaw stems from inadequate validation of software packages, enabling an attacker to place a specially crafted file in a designated location on the device. Successful exploitation of this vulnerability could lead to an attacker overriding the device's standard security mechanisms, resulting in a breach of the chain of trust, which is essential for ensuring the integrity of the operating system.
Affected Version(s)
Cisco IOS XE Software 17.3.1
Cisco IOS XE Software 17.3.2
Cisco IOS XE Software 17.3.3