{"id":"CVE-2025-20327","title":"A vulnerability in the web UI of Cisco IOS Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device.\r\n\r This vulnerability is due to improper input vali…","summary":"A vulnerability in the web UI of Cisco IOS Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device.\r\n\r This vulnerability is due to improper input vali…","severity":"high","cvss":7.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H","cwe":["CWE-1287"],"vendor":"cisco","product":"ios","affected":["ios = 15.2(6)e2","ios = 15.2(6)e2a","ios = 15.2(6)e2b","ios = 15.2(6)e3","ios = 15.2(7)e","ios = 15.2(7)e0a","ios = 15.2(7)e0b","ios = 15.2(7)e0s","ios = 15.2(7)e1","ios = 15.2(7)e1a","ios = 15.2(7)e2","ios = 15.2(7)e2a","ios = 15.2(7)e3","ios = 15.2(7)e3k","ios = 15.2(7)e4","ios = 15.2(7)e5","ios = 15.2(7)e6","ios = 15.2(7)e7","ios = 15.2(7)e8","ios = 15.2(7)e9","ios = 15.2(7)e10","ios = 15.2(7a)e0b","ios = 15.2(7b)e0b","ios = 15.2(8)e","ios = 15.2(8)e1","ios = 15.2(8)e2","ios = 15.2(8)e3","ios = 15.2(8)e4","ios = 15.2(8)e5"],"published":"2025-09-24","updated":"2026-09-17","sourceUpdated":"2026-09-17T19:24:42.800","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-20327","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ios-invalid-url-dos-Nvxszf6u","label":"psirt@cisco.com"}],"tags":["nvd"],"epss":0.00388,"epssPercentile":0.32627,"ingestedAt":"2026-09-17T19:26:25.278Z","slug":"CVE-2025-20327","body":"## Overview\n\nA vulnerability in the web UI of Cisco IOS Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device.\r\n\r This vulnerability is due to improper input validation. An attacker could exploit this vulnerability by sending a crafted URL in an HTTP request. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.\n\n## Affected\n\n- `ios = 15.2(6)e2`\n- `ios = 15.2(6)e2a`\n- `ios = 15.2(6)e2b`\n- `ios = 15.2(6)e3`\n- `ios = 15.2(7)e`\n- `ios = 15.2(7)e0a`\n- `ios = 15.2(7)e0b`\n- `ios = 15.2(7)e0s`\n- `ios = 15.2(7)e1`\n- `ios = 15.2(7)e1a`\n- `ios = 15.2(7)e2`\n- `ios = 15.2(7)e2a`\n- `ios = 15.2(7)e3`\n- `ios = 15.2(7)e3k`\n- `ios = 15.2(7)e4`\n- `ios = 15.2(7)e5`\n- `ios = 15.2(7)e6`\n- `ios = 15.2(7)e7`\n- `ios = 15.2(7)e8`\n- `ios = 15.2(7)e9`\n- `ios = 15.2(7)e10`\n- `ios = 15.2(7a)e0b`\n- `ios = 15.2(7b)e0b`\n- `ios = 15.2(8)e`\n- `ios = 15.2(8)e1`\n- `ios = 15.2(8)e2`\n- `ios = 15.2(8)e3`\n- `ios = 15.2(8)e4`\n- `ios = 15.2(8)e5`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":42.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}