vulnti.work

Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability

Critical Listed in CISA KEV
CVECVE-2025-20352
First seen2025-09-29 00:00 UTC
Disclosed2025-09-29 00:00 UTC
Last updated2026-07-15 01:15 UTC
Channel statuspending_review

Summary

Cisco IOS and IOS XE contains a stack-based buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) subsystem that could allow for denial of service or remote code execution. A successful exploit could allow a low-privileged attacker to cause the affected system to reload, resulting in a DoS condition, or allow a high-privileged attacker to execute arbitrary code as the root user and obtain full control of the affected system.

In-depth triage · Auto channel

No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).

Affected products

  • Cisco:IOS and IOS XE

Sources

  • CISA KEV DATABASE

Original Links

Timeline

  1. kev_added CISA KEV
  2. kev_ingest CISA KEV