CVE-2025-20312 Details
Description
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper error handling when parsing a specific SNMP request. An attacker could exploit this vulnerability by sending a specific SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition. This vulnerability affects SNMP versions 1, 2c, and 3. To exploit this vulnerability through SNMPv2c or earlier, the attacker must know a valid read-write or read-only SNMP community string for the affected system. To exploit this vulnerability through SNMPv3, the attacker must have valid SNMP user credentials for the affected system.
A denial-of-service vulnerability has been identified in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software. This issue allows an authenticated, remote attacker to cause an affected device to reload unexpectedly, leading to a DoS condition. The vulnerability arises from improper error handling when parsing specific SNMP requests. It affects SNMP versions 1, 2c, and 3. Exploitation through SNMPv2c or earlier requires knowledge of a valid read-write or read-only SNMP community string for the affected system. For SNMPv3, valid SNMP user credentials are necessary.
Cisco has released software updates to address this vulnerability. Instructions for upgrading to the fixed software can be found on the Cisco Support and Downloads page. Additionally, as a temporary mitigation, administrators can disable the vulnerable SNMP object identifier (OID) on affected devices.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 24, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snmpwred-x3MJyf5M | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-835 | Loop with Unreachable Exit Condition ('Infinite Loop') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco ios xe | 17.2.1 17.2.1a 17.2.1r 17.2.1v 17.2.2 17.2.3 17.3.1 17.3.1a 17.3.1w 17.3.1x 17.3.1z 17.3.2 17.3.2a 17.3.3 17.3.4 17.3.4a 17.3.4b 17.3.4c 17.3.5 17.3.5a 17.3.5b 17.3.6 17.3.7 17.3.8 17.3.8a 17.4.1 17.4.1a 17.4.1b 17.4.2 17.4.2a 17.5.1 17.5.1a 17.6.1 17.6.1a 17.6.1w 17.6.1x 17.6.1y 17.6.1z 17.6.1z1 17.6.2 17.6.3 17.6.3a 17.6.4 17.6.5 17.6.5a 17.6.6 17.6.6a 17.6.7 17.6.8 17.6.8a 17.7.1 17.7.1a 17.7.1b 17.7.2 17.8.1 17.8.1a 17.9.1 17.9.1a 17.9.1w 17.9.1x 17.9.1x1 17.9.1y 17.9.1y1 17.9.2 17.9.2a 17.9.3 17.9.3a 17.9.4 17.9.4a 17.9.5 17.9.5a 17.9.5b 17.9.5e 17.9.5f 17.9.6 17.9.6a 17.9.7 17.9.7a 17.9.7b 17.10.1 17.10.1a 17.10.1b 17.11.1 17.11.1a 17.12.1 17.12.1a 17.12.1w 17.12.1x 17.12.1y 17.12.1z 17.12.1z1 17.12.1z2 17.12.1z3 17.12.1z4 17.12.2 17.12.2a 17.12.3 17.12.3a 17.12.4 17.12.4a 17.12.4b 17.12.5 17.12.5a 17.12.5b 17.12.5c 17.13.1 17.13.1a 17.14.1 17.14.1a 17.15.1 17.15.1a 17.15.1b 17.15.1w 17.15.1x 17.15.1y 17.15.1z 17.15.2 17.15.2a 17.15.2b 17.15.2c 17.15.3 17.15.3a 17.15.3b 17.16.1 17.16.1a 17.17.1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 26, 2026 | CVE Translated | [email protected] |
| Sep 17, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 24, 2025 | New CVE Received | [email protected] |