Cisco Security Advisory
Follow
Cisco IOS XE Software Secure Boot Bypass Vulnerabilities
Multiple vulnerabilities exist in Cisco IOS XE Software, potentially allowing unauthorized code execution at boot time. These flaws stem from improper validation of software packages. An attacker could exploit them by placing a specially crafted file on an affected device. Successful exploitation enables persistent code execution on the underlying operating system. This bypasses a critical device security feature, leading Cisco to elevate the Security Impact Rating to High. Software updates have been released to fix these vulnerabilities. Unfortunately, there are no workarounds available to mitigate these risks. The specific vulnerabilities are identified as CVE-2025-20313 and CVE-2025-20314. This advisory is part of Cisco's September 2025 security advisory bundled publication. Further details are available on Cisco's security advisory website.