CVE-2025-20200 Details
Description
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15 to elevate privileges to root on the underlying operating system of an affected device. This vulnerability is due to insufficient input validation when processing specific configuration commands. An attacker could exploit this vulnerability by including crafted input in specific configuration commands. A successful exploit could allow the attacker to elevate privileges to root on the underlying operating system of an affected device. The security impact rating (SIR) of this advisory has been raised to High because an attacker could gain access to the underlying operating system of the affected device and perform potentially undetected actions. Note: The attacker must have privileges to enter configuration mode on the affected device. This is usually referred to as privilege level 15.
A vulnerability exists in the CLI of Cisco IOS XE Software, allowing an authenticated, local attacker with privilege level 15 to elevate privileges to root on the underlying operating system of the affected device. This issue arises from inadequate input validation when processing certain configuration commands. An attacker could exploit this vulnerability by injecting crafted input into these commands, potentially leading to unauthorized access and actions at the root level on the device's operating system.
Cisco has released free software updates to address this vulnerability. Customers with service contracts should obtain these updates through their usual channels. For those without service contracts, contact the Cisco Technical Assistance Center (TAC) for assistance. To determine exposure to this vulnerability, use the Cisco Software Checker tool.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 8, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-privesc-su7scvdp | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-754 | Improper Check for Unusual or Exceptional Conditions | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco ios xe | 3.2.0se 3.2.1se 3.2.2se 3.2.3se 3.3.0se 3.3.0sg 3.3.1se 3.3.1sg 3.3.2se 3.3.2sg 3.3.3se 3.3.4se 3.3.5se 3.4.0sg 3.4.1sg 3.4.2sg 3.4.3sg 3.4.4sg 3.4.5sg 3.4.6sg 3.4.7sg 3.4.8sg 3.5.0e 3.5.1e 3.5.2e 3.5.3e 3.6.0e 3.6.1e 3.6.2ae 3.6.2e 3.6.3e 3.6.4e 3.6.5ae 3.6.5be 3.6.5e 3.6.6e 3.6.7be 3.6.7e 3.6.8e 3.6.9e 3.6.10e 3.7.0bs 3.7.0e 3.7.0s 3.7.1as 3.7.1e 3.7.1s 3.7.2e 3.7.2s 3.7.2ts 3.7.3e 3.7.3s 3.7.4as 3.7.4e 3.7.4s 3.7.5e 3.7.5s 3.7.6s 3.7.7s 3.8.0e 3.8.0s 3.8.1e 3.8.1s 3.8.2e 3.8.2s 3.8.3e 3.8.4e 3.8.5ae 3.8.5e 3.8.6e 3.8.7e 3.8.8e 3.8.9e 3.8.10e 3.9.0as 3.9.0e 3.9.0s 3.9.1as 3.9.1e 3.9.1s 3.9.2e 3.9.2s 3.10.0ce 3.10.0e 3.10.1e 3.10.2e 3.10.3e 3.11.0e 3.11.0s 3.11.1ae 3.11.1e 3.11.1s 3.11.2e 3.11.2s 3.11.3ae 3.11.3e 3.11.3s 3.11.4e 3.11.4s 3.11.5e 3.11.6e 3.11.7e 3.11.8e 3.11.9e 3.11.10e 3.11.11e 3.12.0as 3.12.0s 3.12.1s 3.12.2s 3.12.3s 3.12.4s 3.13.0as 3.13.0s 3.13.1s 3.13.2as 3.13.2s 3.13.3s 3.13.4s 3.13.5as 3.13.5s 3.13.6as 3.13.6s 3.13.7as 3.13.7s 3.13.8s 3.13.9s 3.13.10s 3.14.0s 3.14.1s 3.14.2s 3.14.3s 3.14.4s 3.15.0s 3.15.1cs 3.15.1s 3.15.2s 3.15.3s 3.15.4s 3.16.0cs 3.16.0s 3.16.1as 3.16.1s 3.16.2as 3.16.2bs 3.16.2s 3.16.3as 3.16.3s 3.16.4as 3.16.4bs 3.16.4ds 3.16.4s 3.16.5s 3.16.6bs 3.16.6s 3.16.7as 3.16.7bs 3.16.7s 3.16.8s 3.16.9s 3.16.10s 3.17.0s 3.17.1as 3.17.1s 3.17.2s 3.17.3s 3.17.4s 3.18.0as 3.18.0s 3.18.0sp 3.18.1asp 3.18.1bsp 3.18.1csp 3.18.1s 3.18.1sp 3.18.2asp 3.18.2s 3.18.2sp 3.18.3asp 3.18.3bsp 3.18.3s 3.18.3sp 3.18.4s 3.18.4sp 3.18.5sp 3.18.6sp 3.18.7sp 3.18.8asp 3.18.9sp 16.1.1 16.1.2 16.1.3 16.2.1 16.2.2 16.3.1 16.3.1a 16.3.2 16.3.3 16.3.4 16.3.5 16.3.5b 16.3.6 16.3.7 16.3.8 16.3.9 16.3.10 16.3.11 16.4.1 16.4.2 16.4.3 16.5.1 16.5.1a 16.5.1b 16.5.2 16.5.3 16.6.1 16.6.2 16.6.3 16.6.4 16.6.4a 16.6.5 16.6.5a 16.6.6 16.6.7 16.6.8 16.6.9 16.6.10 16.7.1 16.7.1a 16.7.1b 16.7.2 16.7.3 16.7.4 16.8.1 16.8.1a 16.8.1b 16.8.1c 16.8.1d 16.8.1e 16.8.1s 16.8.2 16.8.3 16.9.1 16.9.1a 16.9.1b 16.9.1s 16.9.2 16.9.3 16.9.3a 16.9.4 16.9.5 16.9.5f 16.9.6 16.9.7 16.9.8 16.10.1 16.10.1a 16.10.1b 16.10.1c 16.10.1d 16.10.1e 16.10.1f 16.10.1g 16.10.1s 16.10.2 16.10.3 16.11.1 16.11.1a 16.11.1b 16.11.1s 16.11.2 16.12.1 16.12.1a 16.12.1c 16.12.1s 16.12.1t 16.12.1w 16.12.1x 16.12.1y 16.12.1z1 16.12.1z2 16.12.2 16.12.2a 16.12.2s 16.12.3 16.12.3a 16.12.3s 16.12.4 16.12.4a 16.12.5 16.12.5a 16.12.5b 16.12.6 16.12.6a 16.12.7 16.12.8 16.12.9 16.12.10 16.12.10a 16.12.11 16.12.12 17.1.1 17.1.1a 17.1.1s 17.1.1t 17.1.3 17.2.1 17.2.1a 17.2.1r 17.2.1v 17.2.2 17.2.3 17.3.1 17.3.1a 17.3.1w 17.3.1x 17.3.1z 17.3.2 17.3.2a 17.3.3 17.3.4 17.3.4a 17.3.4b 17.3.4c 17.3.5 17.3.5a 17.3.5b 17.3.6 17.3.7 17.3.8 17.3.8a 17.4.1 17.4.1a 17.4.1b 17.4.2 17.4.2a 17.5.1 17.5.1a 17.6.1 17.6.1a 17.6.1w 17.6.1x 17.6.1y 17.6.1z 17.6.1z1 17.6.2 17.6.3 17.6.3a 17.6.4 17.6.5 17.6.5a 17.6.6 17.6.6a 17.6.7 17.6.8 17.6.8a 17.7.1 17.7.1a 17.7.1b 17.7.2 17.8.1 17.8.1a 17.9.1 17.9.1a 17.9.1w 17.9.1x 17.9.1x1 17.9.1y 17.9.1y1 17.9.2 17.9.2a 17.9.3 17.9.3a 17.9.4 17.9.4a 17.9.5 17.9.5a 17.9.5b 17.9.5e 17.9.5f 17.9.6 17.9.6a 17.10.1 17.10.1a 17.10.1b 17.11.1 17.11.1a 17.11.99sw 17.12.1 17.12.1a 17.12.1w 17.12.1x 17.12.1y 17.12.1z 17.12.1z1 17.12.2 17.12.2a 17.12.3 17.12.3a 17.12.4 17.12.4a 17.12.4b 17.13.1 17.13.1a 17.14.1 17.14.1a 17.15.1 17.15.1a 17.15.1b 17.15.1w |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 11, 2025 | Initial Analysis | [email protected] |
| May 7, 2025 | New CVE Received | [email protected] |