PT-2025-20250 · Cisco · Cisco Ios Xe+1

Published

2025-05-07

·

Updated

2025-08-05

·

CVE-2025-20151

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cisco IOS Software and Cisco IOS XE Software (affected versions not specified)
Description A vulnerability in the implementation of the Simple Network Management Protocol Version 3 (SNMPv3) feature could allow an authenticated, remote attacker to poll an affected device using SNMP, even if the device is configured to deny SNMP traffic from an unauthorized source or the SNMPv3 username is removed from the configuration. This issue exists due to the way that the SNMPv3 configuration is stored in the startup configuration. An attacker could exploit this vulnerability by polling an affected device from a source address that should have been denied, allowing them to perform SNMP operations from a source that should be denied. The attacker must have valid SNMPv3 user credentials to exploit this vulnerability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2025-10318
CVE-2025-20151

Affected Products

Cisco Ios
Cisco Ios Xe