Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2025-20170

Quick assessment

Affected
Cisco IOS
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Cisco IOS等都是美国思科(Cisco)公司的产品。Cisco IOS是一套为其网络设备开发的操作系统。Cisco IOS XR是一套为其网络设备开发的操作系统。Cisco IOS XE是一个操作系统。 Cisco IOS、Cisco IOS XE和Cisco IOS XR存在安全漏洞,该漏洞源于SNMP请求解析错误处理不当,会导致拒绝服务或SNMP进程重启。

CVSS 7.7 · High EPSS 0.78% · P54

Possible ATT&CK Techniques 1 AI

T1499 · Endpoint Denial of Service
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-20170

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition.  This vulnerability affects SNMP versions 1, 2c, and 3. To exploit this vulnerability through SNMP v2c or earlier, the attacker must know a valid read-write or read-only SNMP community string for the affected system. To exploit this vulnerability through SNMP v3, the attacker must have valid SNMP user credentials for the affected system.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Cisco IOS、Cisco IOS XE和Cisco IOS XR 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Cisco IOS等都是美国思科(Cisco)公司的产品。Cisco IOS是一套为其网络设备开发的操作系统。Cisco IOS XR是一套为其网络设备开发的操作系统。Cisco IOS XE是一个操作系统。 Cisco IOS、Cisco IOS XE和Cisco IOS XR存在安全漏洞,该漏洞源于SNMP请求解析错误处理不当,会导致拒绝服务或SNMP进程重启。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Cisco IOS 12.2(4)B -
Cisco Cisco IOS XE Software 3.2.0SG -

II. Public POCs for CVE-2025-20170

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-20170

请登录查看更多情报信息。

Vendor Advisories for CVE-2025-20170 (1)

Same Patch Batch · Cisco · 2025-02-05 · 18 CVEs total

CVE-2025-20124 9.9 CRITICAL Cisco Identity Services Engine Java Deserialization Vulnerability
CVE-2025-20125 9.1 CRITICAL Cisco Identity Services Engine Insufficient Authorization Bypass Vulnerability
CVE-2025-20175 7.7 HIGH Cisco IOS和Cisco IOS XE 安全漏洞
CVE-2025-20173 7.7 HIGH Cisco IOS和Cisco IOS XE 安全漏洞
CVE-2025-20172 7.7 HIGH Cisco IOS、Cisco IOS XE和Cisco IOS XR 安全漏洞
CVE-2025-20176 7.7 HIGH Cisco IOS和Cisco IOS XE 安全漏洞
CVE-2025-20171 7.7 HIGH Cisco多款产品 安全漏洞
CVE-2025-20174 7.7 HIGH Cisco IOS和Cisco IOS XE 安全漏洞
CVE-2025-20169 7.7 HIGH Cisco IOS、Cisco IOS XE和Cisco IOS XR 安全漏洞
CVE-2025-20184 6.5 MEDIUM Cisco Secure Email and Web Manager and Secure Web Appliance Command Injection Vulnerabilit
CVE-2025-20179 6.1 MEDIUM Cisco Expressway Series Cross-Site Scripting Vulnerability
CVE-2025-20183 5.8 MEDIUM Cisco Secure Web Appliance Range Request Bypass Vulnerability
CVE-2025-20205 4.8 MEDIUM Cisco Identity Services Engine 跨站脚本漏洞
CVE-2025-20204 4.8 MEDIUM Cisco Identity Services Engine 跨站脚本漏洞
CVE-2025-20180 4.8 MEDIUM Cisco Secure Email and Web Manager and Secure Email Gateway Cross-Site Scripting Vulnerabi
CVE-2025-20207 4.3 MEDIUM Cisco Secure Email Gateway, Cisco Secure Email and Web Appliance and Cisco Secure Web Appl
CVE-2025-20185 3.4 LOW Cisco Secure Email and Web Manager, Secure Email Gateway, and Secure Web Appliance Privile

IV. Related Vulnerabilities

V. Comments for CVE-2025-20170

No comments yet


Leave a comment