5.3
CVE-2025-20196
- EPSS 0.05%
- Published 07.05.2025 17:38:10
- Last modified 11.07.2025 14:55:33
- Source psirt@cisco.com
- Teams watchlist Login
- Open Login
A vulnerability in the Cisco IOx application hosting environment of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the Cisco IOx application hosting environment to stop responding, resulting in a denial of service (DoS) condition. This vulnerability is due to the improper handling of HTTP requests. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to cause the Cisco IOx application hosting environment to stop responding. The IOx process will need to be manually restarted to recover services.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users. Login
Data is provided by the National Vulnerability Database (NVD)
Cisco ≫ Cgr1000 Firmware Version < 15.9\(3\)m12
Cisco ≫ Ir510 Wpan Firmware Version-
Cisco ≫ Ic3000 Industrial Compute Gateway Firmware Version < 1.5.2
Cisco ≫ 807 Industrial Integrated Services Router Firmware Version < 15.9\(3\)m11
Cisco ≫ 809 Industrial Integrated Services Router Firmware Version < 15.9\(3\)m11
Cisco ≫ 829 Industrial Integrated Services Router Firmware Version < 15.9\(3\)m11
Cisco ≫ Ios Xe Version < 17.15.2
Cisco ≫ Catalyst 9100 Version-
Cisco ≫ Catalyst 9105 Version-
Cisco ≫ Catalyst 9105ax Version-
Cisco ≫ Catalyst 9105axi Version-
Cisco ≫ Catalyst 9105axw Version-
Cisco ≫ Catalyst 9105i Version-
Cisco ≫ Catalyst 9105w Version-
Cisco ≫ Catalyst 9115 Version-
Cisco ≫ Catalyst 9115 Ap Version-
Cisco ≫ Catalyst 9115ax Version-
Cisco ≫ Catalyst 9115axe Version-
Cisco ≫ Catalyst 9115axi Version-
Cisco ≫ Catalyst 9117 Version-
Cisco ≫ Catalyst 9117 Ap Version-
Cisco ≫ Catalyst 9117ax Version-
Cisco ≫ Catalyst 9117axi Version-
Cisco ≫ Catalyst 9120 Version-
Cisco ≫ Catalyst 9120 Ap Version-
Cisco ≫ Catalyst 9120ax Version-
Cisco ≫ Catalyst 9120axe Version-
Cisco ≫ Catalyst 9120axi Version-
Cisco ≫ Catalyst 9120axp Version-
Cisco ≫ Catalyst 9124 Version-
Cisco ≫ Catalyst 9124ax Version-
Cisco ≫ Catalyst 9124axd Version-
Cisco ≫ Catalyst 9124axi Version-
Cisco ≫ Catalyst 9124d Version-
Cisco ≫ Catalyst 9124e Version-
Cisco ≫ Catalyst 9124i Version-
Cisco ≫ Catalyst 9130 Version-
Cisco ≫ Catalyst 9130 Ap Version-
Cisco ≫ Catalyst 9130ax Version-
Cisco ≫ Catalyst 9130axe Version-
Cisco ≫ Catalyst 9130axi Version-
Cisco ≫ Catalyst 9136 Version-
Cisco ≫ Catalyst 9162 Version-
Cisco ≫ Catalyst 9164 Version-
Cisco ≫ Catalyst 9166 Version-
Cisco ≫ Catalyst 9166d1 Version-
Cisco ≫ Catalyst 9105 Version-
Cisco ≫ Catalyst 9105ax Version-
Cisco ≫ Catalyst 9105axi Version-
Cisco ≫ Catalyst 9105axw Version-
Cisco ≫ Catalyst 9105i Version-
Cisco ≫ Catalyst 9105w Version-
Cisco ≫ Catalyst 9115 Version-
Cisco ≫ Catalyst 9115 Ap Version-
Cisco ≫ Catalyst 9115ax Version-
Cisco ≫ Catalyst 9115axe Version-
Cisco ≫ Catalyst 9115axi Version-
Cisco ≫ Catalyst 9117 Version-
Cisco ≫ Catalyst 9117 Ap Version-
Cisco ≫ Catalyst 9117ax Version-
Cisco ≫ Catalyst 9117axi Version-
Cisco ≫ Catalyst 9120 Version-
Cisco ≫ Catalyst 9120 Ap Version-
Cisco ≫ Catalyst 9120ax Version-
Cisco ≫ Catalyst 9120axe Version-
Cisco ≫ Catalyst 9120axi Version-
Cisco ≫ Catalyst 9120axp Version-
Cisco ≫ Catalyst 9124 Version-
Cisco ≫ Catalyst 9124ax Version-
Cisco ≫ Catalyst 9124axd Version-
Cisco ≫ Catalyst 9124axi Version-
Cisco ≫ Catalyst 9124d Version-
Cisco ≫ Catalyst 9124e Version-
Cisco ≫ Catalyst 9124i Version-
Cisco ≫ Catalyst 9130 Version-
Cisco ≫ Catalyst 9130 Ap Version-
Cisco ≫ Catalyst 9130ax Version-
Cisco ≫ Catalyst 9130axe Version-
Cisco ≫ Catalyst 9130axi Version-
Cisco ≫ Catalyst 9136 Version-
Cisco ≫ Catalyst 9162 Version-
Cisco ≫ Catalyst 9164 Version-
Cisco ≫ Catalyst 9166 Version-
Cisco ≫ Catalyst 9166d1 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.05% | 0.155 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
psirt@cisco.com | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
|
CWE-307 Improper Restriction of Excessive Authentication Attempts
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.