Record summary
A quick snapshot of what this page covers.
Vulnerability status
How serious this vulnerability is and whether it is known to be exploited.
- CVE ID
- CVE-2025-20352
- Vendor/project
- Cisco
- Product
- IOS and IOS XE
- Vulnerability name
- Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability
- Date added
- 2025-09-29
- Due date
- 2025-10-20
- Known ransomware campaign use
- Unknown
Exploit context
What the vulnerability is about.
Cisco IOS and IOS XE contains a stack-based buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) subsystem that could allow for denial of service or remote code execution. A successful exploit could allow a low-privileged attacker to cause the affected system to reload, resulting in a DoS condition, or allow a high-privileged attacker to execute arbitrary code as the root user and obtain full control of the affected system.
Source
Where this page information comes from.
Original source
Original source links
Open the public records and source datasets used for this page.