PT-2025-20250 · Cisco · Cisco Ios Xe+1
Published
2025-05-07
·
Updated
2025-08-05
·
CVE-2025-20151
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco IOS Software and Cisco IOS XE Software (affected versions not specified)
Description
A vulnerability in the implementation of the Simple Network Management Protocol Version 3 (SNMPv3) feature could allow an authenticated, remote attacker to poll an affected device using SNMP, even if the device is configured to deny SNMP traffic from an unauthorized source or the SNMPv3 username is removed from the configuration. This issue exists due to the way that the SNMPv3 configuration is stored in the startup configuration. An attacker could exploit this vulnerability by polling an affected device from a source address that should have been denied, allowing them to perform SNMP operations from a source that should be denied. The attacker must have valid SNMPv3 user credentials to exploit this vulnerability.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Ios
Cisco Ios Xe