CVE-2025-20352

Published Sep 24, 2025

Last updated 12 hours ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-20352 is a vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software. It stems from a stack overflow condition. An attacker can exploit this vulnerability by sending a crafted SNMP packet to an affected device over IPv4 or IPv6 networks. Cisco confirmed that the vulnerability is being actively exploited in the wild. The vulnerability allows for two distinct attack scenarios based on the attacker's privilege level. A low-privileged, authenticated, remote attacker with an SNMPv2c read-only community string or valid SNMPv3 user credentials can cause a denial-of-service (DoS) condition on an affected device. A high-privileged attacker with SNMPv1 or v2c read-only community strings combined with administrative credentials can execute code as the root user, gaining full control of the affected system.

Description
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following: An authenticated, remote attacker with low privileges could cause a denial of service (DoS) condition on an affected device that is running Cisco IOS Software or Cisco IOS XE Software. To cause the DoS, the attacker must have the SNMPv2c or earlier read-only community string or valid SNMPv3 user credentials. An authenticated, remote attacker with high privileges could execute code as the root user on an affected device that is running Cisco IOS XE Software. To execute code as the root user, the attacker must have the SNMPv1 or v2c read-only community string or valid SNMPv3 user credentials and administrative or privilege 15 credentials on the affected device. An attacker could exploit this vulnerability by sending a crafted SNMP packet to an affected device over IPv4 or IPv6 networks. This vulnerability is due to a stack overflow condition in the SNMP subsystem of the affected software. A successful exploit could allow a low-privileged attacker to cause the affected system to reload, resulting in a DoS condition, or allow a high-privileged attacker to execute arbitrary code as the root user and obtain full control of the affected system. Note: This vulnerability affects all versions of SNMP.
Source
psirt@cisco.com
NVD status
Analyzed
Products
ios, ios_xe, ios_xe_sd-wan

Risk scores

CVSS 3.1

Type
Primary
Base score
7.7
Impact score
4
Exploitability score
3.1
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Severity
HIGH

Weaknesses

psirt@cisco.com
CWE-121

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

33

  1. Cisco IOS/IOS XE の SNMPに脆弱性(CVE-2025-20352) https://t.co/hno7VT3pZk #セキュリティ対策Lab #セキュリティ #Security

    @securityLab_jp

    26 Sept 2025

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Ciscoが警告するSNMP脆弱性CVE-2025-20352によるRCEとDoSの危険性 https://t.co/WCKbChgShF #Security #セキュリティー #ニュース

    @SecureShield_

    26 Sept 2025

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. ”政府機関または民間企業を標的としてきたサイバースパイグループの詳細が明らかになり、その実態は中国の国家支援型脅威アクター” IOSとはシスコシステムズ社製ルーターのアプリ(OS)の事ですね シス

    @NSaito_tokyo

    26 Sept 2025

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Fun day today. CVE-2025-20334 CVE-2025-20315 CVE-2025-20160 CVE-2025-20352 CVE-2025-20327 CVE-2025-20312 CVE-2025-20311 CVE-2025-20313 CVE-2025-20314 CVE-2025-20149 CVE-2025-20240 CVE-2025-20338 CVE-2025-20293 CVE-2025-20316 @grok , how much of a pain in the ass are these vulns

    @leftSECURE

    25 Sept 2025

    46 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  5. Big news in network land: Cisco fixed a critical SNMP flaw in IOS software, CVE-2025-20352, after it was exploited in the wild for RCE or DoS attacks. No more free passes.

    @codeaetheris

    25 Sept 2025

    46 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 🚨 A critical zero-day vulnerability in Cisco IOS is on the loose! CVE-2025-20352 has a CVSS score of 7.7 and is actively exploited. Are you prepared? #Cybersecurity #Cisco https://t.co/8AY8ZBlQnc

    @Cyb3r_5wift

    25 Sept 2025

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 🛡️ Cisco IOS bajo ataque: un solo paquete SNMP puede dar control total Cisco confirmó una vulnerabilidad grave (CVE-2025-20352) en sus sistemas IOS e IOS XE. Además que ya fue usada en ataques reales. El problema está en cómo manejan el protocolo SNMP (el que usan los

    @CycuraMX

    25 Sept 2025

    885 Impressions

    5 Retweets

    16 Likes

    4 Bookmarks

    0 Replies

    0 Quotes

  8. Mapping CVE-2025-20352 Exposure with MDE Telemetry Cisco has confirmed active exploitation of CVE-2025-20352—a zero-day vulnerability affecting its widely deployed IOS and IOS XE platforms. To help defenders assess their exposure, I’ve developed a KQL leveraging Microsoft ht

    @0x534c

    25 Sept 2025

    3325 Impressions

    10 Retweets

    49 Likes

    22 Bookmarks

    0 Replies

    0 Quotes

  9. Cisco issues urgent security updates for CVE-2025-20352, a high-severity zero-day vulnerability in IOS and IOS XE software. The flaw in the SNMP subsystem can lead to DoS attacks or root-level code execution. Upgrade to patched versions now to stay secure. Limit SNMP access to

    @bigmacd16684

    25 Sept 2025

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. Cisco patches 14 vulnerabilities in IOS and IOS XE, including critical CVE-2025-20352, a stack overflow in SNMP allowing DoS or root-level remote code execution. Updates affect multiple Cisco devices. #NetworkSecurity #CiscoPatches #USA https://t.co/7iexyV0YWC

    @TweetThreatNews

    25 Sept 2025

    34 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. Today's top 5 cybersecurity news - September 25, 2025 1. Cisco has disclosed a high-severity vulnerability (CVE-2025-20352, CVSS 7.7) in its IOS and IOS XE Software that is being actively exploited in the wild. The flaw could enable remote attackers to execute arbitrary code or

    @NewsNerdie

    25 Sept 2025

    64 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  12. 🚨 Cisco flaw already under attack: CVE-2025-20352 lets remote hackers crash systems or run code as root via SNMP. Cisco IOS & IOS XE devices with SNMP enabled are at risk—Meraki MS390 & Catalyst 9300 included. Patch to IOS XE 17.15.4a now. #cybernews https://t.co/tg

    @Free713PK

    25 Sept 2025

    71 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. 🚨 𝐂𝐢𝐬𝐜𝐨 𝐒𝐍𝐌𝐏 𝐅𝐥𝐚𝐰 (𝐂𝐕𝐄-𝟐𝟎𝟐𝟓-𝟐𝟎𝟑𝟓𝟐) 𝐀𝐜𝐭𝐢𝐯𝐞𝐥𝐲 𝐄𝐱𝐩𝐥𝐨𝐢𝐭𝐞𝐝: 𝐏𝐚𝐭𝐜𝐡 𝐍𝐨𝐰 𝐭𝐨 𝐒𝐭𝐨𝐩 𝐑𝐨𝐨𝐭 𝐀𝐜𝐜𝐞

    @PurpleOps_io

    25 Sept 2025

    102 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  14. シスコ、悪用が確認されたIOSのゼロデイ脆弱性について警告(CVE-2025-20352) | Codebook https://t.co/ZjTbFKi5qv #izumino_trend

    @sec_trend

    25 Sept 2025

    48 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. CVE-2025-20352: Buffer Overflaw in Cisco IOS XE, 7.7 rating❗️ A vulnerability in the SNMP component allows an attacker to perform a DoS or execute code as the root user. It's already being exploited! Search at https://t.co/hv7QKSqxTR: 👉 Link: https://t.co/Z2FStl4UW3 http

    @Netlas_io

    25 Sept 2025

    641 Impressions

    4 Retweets

    5 Likes

    4 Bookmarks

    0 Replies

    0 Quotes

  16. 📌 سيسكو تحذر من ثغرة أمنية خطيرة في برنامج IOS وبرنامج IOS XE، تسمح لهجوم عن بُعد بتنفيذ تعليمات برمجية عشوائية أو التسبب في انقطاع الخدمة. الثغرة، CVE-2025-20352،

    @Cybercachear

    25 Sept 2025

    102 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. Cisco iOS/iOS XEの脆弱性 CVE-2025-20352 SNMPプロトコルにおけるスタックベースのバッファオーバーフロー 認証を前提としており、低権限ではDoS、高権限では任意コード実行が可能。 悪用事例あり。また、PoCコード

    @GenKa_232

    25 Sept 2025

    60 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. Cisco warns of IOS zero-day vulnerability exploited in attacks. Cisco has released security updates to address a high-severity zero-day vulnerability tracked as CVE-2025-20352 in Cisco IOS and IOS XE Software that is currently being exploited in attacks. https://t.co/dpR8bucMUr h

    @riskigy

    25 Sept 2025

    128 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  19. CVE-2025-20352 A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following: An authenti… https://t.co/ZTrVlZFWvT

    @CVEnew

    24 Sept 2025

    334 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. CiscoのIOSおよびIOS XEにゼロデイ脆弱性CVE-2025-20352が発覚し、実際に悪用されていることが確認された。問題はSNMPサブシステムに存在し、RCEまたはDoSを引き起こす可能性がある。

    @yousukezan

    24 Sept 2025

    1374 Impressions

    4 Retweets

    8 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  21. 🔥 𝐂𝐢𝐬𝐜𝐨 𝐰𝐚𝐫𝐧𝐬 𝐨𝐟 𝐈𝐎𝐒 𝐳𝐞𝐫𝐨-𝐝𝐚𝐲 𝐯𝐮𝐥𝐧𝐞𝐫𝐚𝐛𝐢𝐥𝐢𝐭𝐲 𝐞𝐱𝐩𝐥𝐨𝐢𝐭𝐞𝐝 𝐢𝐧 𝐚𝐭𝐭𝐚𝐜𝐤𝐬 • CVE-2025-20352 is being actively exploited.

    @PurpleOps_io

    24 Sept 2025

    75 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  22. Cisco patches zero-day vulnerability CVE-2025-20352 in IOS and IOS XE affecting SNMP-enabled devices. Low-privilege attackers can cause DoS, high-privilege can gain full control. #ZeroDay #NetworkSecurity #USA https://t.co/QjVUd2vD1W

    @TweetThreatNews

    24 Sept 2025

    26 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. 0-Day Alert 🚨 Actor exploiting Cisco IOS / XE zero-day (CVE-2025-20352)O. Patches are available now. Our Cisco IOS honeypot contains the SNMP service, making it viable to tracking this exploit! 👉https://t.co/GXFaqghsXI https://t.co/7EvnMYEquc

    @DefusedCyber

    24 Sept 2025

    12851 Impressions

    48 Retweets

    175 Likes

    64 Bookmarks

    2 Replies

    2 Quotes

  24. ⚠️ Cisco IOS 0-Day RCE Vulnerability Actively Exploited in the Wild Read more: https://t.co/4Wo9IudeJs Cisco has disclosed a zero-day vulnerability, CVE-2025-20352, in its widely used IOS and IOS XE software, confirming it is being actively exploited in the wild. The flaw

    @The_Cyber_News

    24 Sept 2025

    3976 Impressions

    34 Retweets

    95 Likes

    34 Bookmarks

    0 Replies

    0 Quotes

  25. 🚨 Cisco warns of a critical zero-day vuln (CVE-2025-20352) in IOS/IOS XE SNMP subsystem. actively exploited! Low-priv attack DoS; high-priv ones execute root code. Targets: any SNMP-enabled device. Patch NOW! 🔒 Details: https://t.co/0h00VYAbFU #Cybersecurity #Cisco #ZeroDay

    @_F2po_

    24 Sept 2025

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. Fuck you too, Kevin. You guys really that mad? There's an vuln in Cisco IOS which allows RCE via SNMPv1 or v2 if you have the read-only community string and can send SNMP packets. Under active exploitation. CVE-2025-20352 https://t.co/SDFvHjoxQo

    @PokemonRCool13

    24 Sept 2025

    49 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

Configurations