Cisco IOS and IOS XE Software ... Note

Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability

A critical vulnerability has been discovered in Cisco IOS Software and Cisco IOS XE Software affecting the SNMP subsystem. This flaw, identified as CVE-2025-20352, stems from a stack overflow condition. Low-privileged authenticated remote attackers can exploit this to cause a denial of service by triggering a system reload. They require read-only SNMPv2c community strings or valid SNMPv3 credentials for this attack. High-privileged authenticated remote attackers can achieve code execution as the root user on affected devices. This requires administrative or privilege 15 credentials in addition to SNMPv1/v2c read-only community strings or valid SNMPv3 credentials. Attackers can exploit this by sending specially crafted SNMP packets over IPv4 or IPv6. The vulnerability affects all SNMP versions. Cisco has released software updates to address this vulnerability. There are no workarounds, but a mitigation is available. The security impact rating for this vulnerability is High.