7.7

CVE-2025-20312

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.

 This vulnerability is due to improper error handling when parsing a specific SNMP request. An attacker could exploit this vulnerability by sending a specific SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition.

 This vulnerability affects SNMP versions 1, 2c, and 3. To exploit this vulnerability through SNMPv2c or earlier, the attacker must know a valid read-write or read-only SNMP community string for the affected system. To exploit this vulnerability through SNMPv3, the attacker must have valid SNMP user credentials for the affected system.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerCisco
Produkt Cisco IOS XE Software
Version 17.2.1
Status affected
Version 17.2.1r
Status affected
Version 17.2.1a
Status affected
Version 17.2.1v
Status affected
Version 17.2.2
Status affected
Version 17.2.3
Status affected
Version 17.3.1
Status affected
Version 17.3.2
Status affected
Version 17.3.3
Status affected
Version 17.3.1a
Status affected
Version 17.3.1w
Status affected
Version 17.3.2a
Status affected
Version 17.3.1x
Status affected
Version 17.3.1z
Status affected
Version 17.3.4
Status affected
Version 17.3.5
Status affected
Version 17.3.4a
Status affected
Version 17.3.6
Status affected
Version 17.3.4b
Status affected
Version 17.3.4c
Status affected
Version 17.3.5a
Status affected
Version 17.3.5b
Status affected
Version 17.3.7
Status affected
Version 17.3.8
Status affected
Version 17.3.8a
Status affected
Version 17.4.1
Status affected
Version 17.4.2
Status affected
Version 17.4.1a
Status affected
Version 17.4.1b
Status affected
Version 17.4.2a
Status affected
Version 17.5.1
Status affected
Version 17.5.1a
Status affected
Version 17.6.1
Status affected
Version 17.6.2
Status affected
Version 17.6.1w
Status affected
Version 17.6.1a
Status affected
Version 17.6.1x
Status affected
Version 17.6.3
Status affected
Version 17.6.1y
Status affected
Version 17.6.1z
Status affected
Version 17.6.3a
Status affected
Version 17.6.4
Status affected
Version 17.6.1z1
Status affected
Version 17.6.5
Status affected
Version 17.6.6
Status affected
Version 17.6.6a
Status affected
Version 17.6.5a
Status affected
Version 17.6.7
Status affected
Version 17.6.8
Status affected
Version 17.6.8a
Status affected
Version 17.7.1
Status affected
Version 17.7.1a
Status affected
Version 17.7.1b
Status affected
Version 17.7.2
Status affected
Version 17.10.1
Status affected
Version 17.10.1a
Status affected
Version 17.10.1b
Status affected
Version 17.8.1
Status affected
Version 17.8.1a
Status affected
Version 17.9.1
Status affected
Version 17.9.1w
Status affected
Version 17.9.2
Status affected
Version 17.9.1a
Status affected
Version 17.9.1x
Status affected
Version 17.9.1y
Status affected
Version 17.9.3
Status affected
Version 17.9.2a
Status affected
Version 17.9.1x1
Status affected
Version 17.9.3a
Status affected
Version 17.9.4
Status affected
Version 17.9.1y1
Status affected
Version 17.9.5
Status affected
Version 17.9.4a
Status affected
Version 17.9.5a
Status affected
Version 17.9.5b
Status affected
Version 17.9.6
Status affected
Version 17.9.6a
Status affected
Version 17.9.7
Status affected
Version 17.9.5e
Status affected
Version 17.9.5f
Status affected
Version 17.9.7a
Status affected
Version 17.9.7b
Status affected
Version 17.11.1
Status affected
Version 17.11.1a
Status affected
Version 17.12.1
Status affected
Version 17.12.1w
Status affected
Version 17.12.1a
Status affected
Version 17.12.1x
Status affected
Version 17.12.2
Status affected
Version 17.12.3
Status affected
Version 17.12.2a
Status affected
Version 17.12.1y
Status affected
Version 17.12.1z
Status affected
Version 17.12.4
Status affected
Version 17.12.3a
Status affected
Version 17.12.1z1
Status affected
Version 17.12.1z2
Status affected
Version 17.12.4a
Status affected
Version 17.12.5
Status affected
Version 17.12.4b
Status affected
Version 17.12.1z3
Status affected
Version 17.12.5a
Status affected
Version 17.12.1z4
Status affected
Version 17.12.5b
Status affected
Version 17.12.5c
Status affected
Version 17.13.1
Status affected
Version 17.13.1a
Status affected
Version 17.14.1
Status affected
Version 17.14.1a
Status affected
Version 17.15.1
Status affected
Version 17.15.1w
Status affected
Version 17.15.1a
Status affected
Version 17.15.2
Status affected
Version 17.15.1b
Status affected
Version 17.15.1x
Status affected
Version 17.15.1z
Status affected
Version 17.15.3
Status affected
Version 17.15.2c
Status affected
Version 17.15.2a
Status affected
Version 17.15.1y
Status affected
Version 17.15.2b
Status affected
Version 17.15.3a
Status affected
Version 17.15.3b
Status affected
Version 17.16.1
Status affected
Version 17.16.1a
Status affected
Version 17.17.1
Status affected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.22% 0.442
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
psirt@cisco.com 7.7 3.1 4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.