CVE-2025-20352
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the…
Browse: All 2025 CVEs · All vendors
- CVSS score
- 7.7 High
- CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H- CISA KEV
- Yes — actively exploited (added 2025-09-29, remediation due 2025-10-20)
- Weakness (CWE)
- CWE-121
- Published
- 2025-09-24
- Last modified
- 2026-06-17
- NVD status
- Analyzed
Description
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following: An authenticated, remote attacker with low privileges could cause a denial of service (DoS) condition on an affected device that is running Cisco IOS Software or Cisco IOS XE Software. To cause the DoS, the attacker must have the SNMPv2c or earlier read-only community string or valid SNMPv3 user credentials. An authenticated, remote attacker with high privileges could execute code as the root user on an affected device that is running Cisco IOS XE Software. To execute code as the root user, the attacker must have the SNMPv1 or v2c read-only community string or valid SNMPv3 user credentials and administrative or privilege 15 credentials on the affected device. An attacker could exploit this vulnerability by sending a crafted SNMP packet to an affected device over IPv4 or IPv6 networks. This vulnerability is due to a stack overflow condition in the SNMP subsystem of the affected software. A successful exploit could allow a low-privileged attacker to cause the affected system to reload, resulting in a DoS condition, or allow a high-privileged attacker to execute arbitrary code as the root user and obtain full control of the affected system. Note: This vulnerability affects all versions of SNMP.
Affected products
- cisco ios xe sd-wan
- cisco ios xe
- cisco ios
Affected ranges per NVD CPE data; confirm exact versions in the vendor advisory.
Required action (CISA)
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal remediation deadline: 2025-10-20.
How to prioritize this
This vulnerability is on the CISA KEV list, meaning it is being actively exploited — treat it as urgent regardless of the raw CVSS number. Use the live CVE lookup for the latest NVD data, and the CVSS 3.1 calculator to model your own environmental score.
References
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snmp-x4LPhte
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-20352
FAQ
Is CVE-2025-20352 actively exploited?
Yes. CISA added CVE-2025-20352 to its Known Exploited Vulnerabilities (KEV) catalog on 2025-09-29, with a federal remediation deadline of 2025-10-20. A KEV listing means real-world exploitation is confirmed, so patching this should be prioritized above many higher-CVSS bugs that aren't being exploited.
What is the CVSS score of CVE-2025-20352?
CVE-2025-20352 has a CVSS base score of 7.7 (High). Its vector string is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H.
Related vulnerabilities
- CVE-2023-20109 — Cisco IOS and IOS XE
- CVE-2017-3881 — Cisco IOS and IOS XE
- CVE-2018-0171 — Cisco IOS and IOS XE
- CVE-2026-20349 — Cisco Secure Firewall Adaptive Security Ap
- CVE-2026-20316 — Cisco Secure Firewall Management Center (F
- CVE-2008-4128 — Cisco IOS
Data source: NVD & CISA KEV. Shown as-is; nothing added. Last generated from NVD data — re-check the live tool for updates.
weekly kev brief
Patch what's actually being exploited.
One email a week: the KEV additions that matter, prioritized — no noise.
Free. No spam. Unsubscribe anytime. Delivered by Beehiiv.