CVE-2025-20312High· 7.7▾ TwilightA vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability i…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 17.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
0.4% → 0.4%
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to improper error handling when parsing a specific SNMP request. An attacker could exploit this vulnerability by sending a specific SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition.
This vulnerability affects SNMP versions 1, 2c, and 3. To exploit this vulnerability through SNMPv2c or earlier, the attacker must know a valid read-write or read-only SNMP community string for the affected system. To exploit this vulnerability through SNMPv3, the attacker must have valid SNMP user credentials for the affected system.
ios_xe = 17.2.1ios_xe = 17.2.1aios_xe = 17.2.1rios_xe = 17.2.1vios_xe = 17.2.2ios_xe = 17.2.3ios_xe = 17.3.1ios_xe = 17.3.1aios_xe = 17.3.1wios_xe = 17.3.1xios_xe = 17.3.1zios_xe = 17.3.2ios_xe = 17.3.2aios_xe = 17.3.3ios_xe = 17.3.4ios_xe = 17.3.4aios_xe = 17.3.4bios_xe = 17.3.4cios_xe = 17.3.5ios_xe = 17.3.5aios_xe = 17.3.5bios_xe = 17.3.6ios_xe = 17.3.7ios_xe = 17.3.8ios_xe = 17.3.8aios_xe = 17.4.1ios_xe = 17.4.1aios_xe = 17.4.1bios_xe = 17.4.2ios_xe = 17.4.2aios_xe = 17.5.1ios_xe = 17.5.1aios_xe = 17.6.1ios_xe = 17.6.1aios_xe = 17.6.1wios_xe = 17.6.1xios_xe = 17.6.1yios_xe = 17.6.1zios_xe = 17.6.1z1ios_xe = 17.6.2ios_xe = 17.6.3ios_xe = 17.6.3aios_xe = 17.6.4ios_xe = 17.6.5ios_xe = 17.6.5aios_xe = 17.6.6ios_xe = 17.6.6aios_xe = 17.6.7ios_xe = 17.6.8ios_xe = 17.6.8aios_xe = 17.7.1ios_xe = 17.7.1aios_xe = 17.7.1bios_xe = 17.7.2ios_xe = 17.8.1ios_xe = 17.8.1aios_xe = 17.9.1ios_xe = 17.9.1aios_xe = 17.9.1wios_xe = 17.9.1xios_xe = 17.9.1x1ios_xe = 17.9.1yios_xe = 17.9.1y1ios_xe = 17.9.2ios_xe = 17.9.2aios_xe = 17.9.3ios_xe = 17.9.3aios_xe = 17.9.4ios_xe = 17.9.4aios_xe = 17.9.5ios_xe = 17.9.5aios_xe = 17.9.5bios_xe = 17.9.5eios_xe = 17.9.5fios_xe = 17.9.6ios_xe = 17.9.6aios_xe = 17.9.7ios_xe = 17.9.7aios_xe = 17.9.7bios_xe = 17.10.1ios_xe = 17.10.1aios_xe = 17.10.1bios_xe = 17.11.1ios_xe = 17.11.1aios_xe = 17.12.1ios_xe = 17.12.1aios_xe = 17.12.1wios_xe = 17.12.1xios_xe = 17.12.1yios_xe = 17.12.1zios_xe = 17.12.1z1ios_xe = 17.12.1z2ios_xe = 17.12.1z3ios_xe = 17.12.1z4ios_xe = 17.12.2ios_xe = 17.12.2aios_xe = 17.12.3ios_xe = 17.12.3aios_xe = 17.12.4ios_xe = 17.12.4aRefer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-20311High· 7.4A vulnerability in the handling of certain Ethernet frames in Cisco IOS XE Software for Catalyst 9000 Series Switches could allow an unauthenticated, adjacent attacker to cause an egress port to become blocked and drop all outbound traff…
CVE-2026-20124High· 7.7A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. …
CVE-2025-20313Medium· 6.7Multiple vulnerabilities in Cisco IOS XE Software of could allow an authenticated, local attacker with level-15 privileges or an unauthenticated attacker with physical access to the device to execute persistent code at boot time and brea…
CVE-2026-20154High· 8.6A vulnerability in the system rate-limiting process for syslog message 419002 of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, rem…
CVE-2026-20054Medium· 5.8Multiple Cisco products are affected by a vulnerability in the Snort 3 VBA feature that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash. This vulnerability is due to improper error …
CVE-2026-20272Critical· 9.8As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review