CVE-2025-20151
published 2025-05-07CVE-2025-20151: A vulnerability in the implementation of the Simple Network Management Protocol Version 3 (SNMPv3) feature of Cisco IOS Software and Cisco IOS XE Software…
PriorityP425medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
EPSS
0.33%
24.8th percentile
A vulnerability in the implementation of the Simple Network Management Protocol Version 3 (SNMPv3) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to poll an affected device using SNMP, even if the device is configured to deny SNMP traffic from an unauthorized source or the SNMPv3 username is removed from the configuration.
This vulnerability exists because of the way that the SNMPv3 configuration is stored in the Cisco IOS Software and Cisco IOS XE Software startup configuration. An attacker could exploit this vulnerability by polling an affected device from a source address that should have been denied. A successful exploit could allow the attacker to perform SNMP operations from a source that should be denied.
Note: The attacker has no control of the SNMPv3 configuration. To exploit this vulnerability, the attacker must have valid SNMPv3 user credentials.
For more information, see the section of this advisory.
Affected
61 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_ios_xe_catalyst_sd-wan | — | — |
| cisco | cisco_ios_xe_catalyst_sd-wan | — | — |
| cisco | cisco_ios_xe_catalyst_sd-wan | — | — |
| cisco | cisco_ios_xe_catalyst_sd-wan | — | — |
| cisco | cisco_ios_xe_catalyst_sd-wan | — | — |
| cisco | cisco_ios_xe_catalyst_sd-wan | — | — |
| cisco | cisco_ios_xe_catalyst_sd-wan | — | — |
| cisco | cisco_ios_xe_catalyst_sd-wan | — | — |
| cisco | cisco_ios_xe_catalyst_sd-wan | — | — |
| cisco | cisco_ios_xe_catalyst_sd-wan | — | — |
| cisco | cisco_ios_xe_catalyst_sd-wan | — | — |
| cisco | cisco_ios_xe_catalyst_sd-wan | — | — |
| cisco | cisco_ios_xe_catalyst_sd-wan | — | — |
| cisco | cisco_ios_xe_catalyst_sd-wan | — | — |
| cisco | cisco_ios_xe_catalyst_sd-wan | — | — |
| cisco | cisco_ios_xe_catalyst_sd-wan | — | — |
| cisco | cisco_ios_xe_catalyst_sd-wan | — | — |
| cisco | cisco_ios_xe_catalyst_sd-wan | — | — |
| cisco | cisco_ios_xe_catalyst_sd-wan | — | — |
| cisco | cisco_ios_xe_catalyst_sd-wan | — | — |
| cisco | cisco_ios_xe_catalyst_sd-wan | — | — |
| cisco | cisco_ios_xe_catalyst_sd-wan | — | — |
| cisco | cisco_ios_xe_catalyst_sd-wan | — | — |
| cisco | cisco_ios_xe_catalyst_sd-wan | — | — |
| cisco | cisco_ios_xe_catalyst_sd-wan | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v3x4-26xj-qrvg: A vulnerability in the implementation of the Simple Network Management Protocol Version 3 (SNMPv3) feature of Cisco IOS Software and Cisco IOS XE Soft
ghsa_unreviewed·2025-05-07
CVE-2025-20151 [MEDIUM] CWE-1284 GHSA-v3x4-26xj-qrvg: A vulnerability in the implementation of the Simple Network Management Protocol Version 3 (SNMPv3) feature of Cisco IOS Software and Cisco IOS XE Soft
A vulnerability in the implementation of the Simple Network Management Protocol Version 3 (SNMPv3) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to poll an affected device using SNMP, even if the device is configured to deny SNMP traffic from an unauthorized source or the SNMPv3 username is removed from the configuration.
This vulnerability exists because of the way that the SNMPv3 configuration is stored in the Cisco IOS Software and Cisco IOS XE Software startup configuration. An attacker could exploit this vulnerability by polling an affected device from a source address that should have been denied. A successful exploit could allow the attacker to perform SNMP operations from a source that should be denied.
Note: The attacker has
Cisco
Cisco IOS and IOS XE Software SNMPv3 Configuration Restriction Vulnerability
vendor_cisco·2025-05-07·CVSS 4.3
CVE-2025-20151 [MEDIUM] CWE-16 Cisco IOS and IOS XE Software SNMPv3 Configuration Restriction Vulnerability
Cisco IOS and IOS XE Software SNMPv3 Configuration Restriction Vulnerability
A vulnerability in the implementation of the Simple Network Management Protocol Version 3 (SNMPv3) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to poll an affected device using SNMP, even if the device is configured to deny SNMP traffic from an unauthorized source or the SNMPv3 username is removed from the configuration.
This vulnerability exists because of the way that the SNMPv3 configuration is stored in the Cisco IOS Software and Cisco IOS XE Software startup configuration. An attacker could exploit this vulnerability by polling an affected device from a source address that should have been denied. A successful exploit could allow the attacker to perfo
Cisco
Cisco IOS and IOS XE Software SNMPv3 Configuration Restriction Vulnerability
vendor_cisco·CVSS 3.1
CVE-2025-20151 Cisco IOS and IOS XE Software SNMPv3 Configuration Restriction Vulnerability
CVE-2025-20151: Cisco IOS and IOS XE Software SNMPv3 Configuration Restriction Vulnerability
A vulnerability in the implementation of the Simple Network Management Protocol Version 3 (SNMPv3) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to poll an affected device using SNMP, even if the device is configured to deny SNMP traffic from an unauthorized source or the SNMPv3 username is removed from the configuration. This vulnerability exists because of the way that the SNMPv3 configuration is stored in the Cisco IOS Software and Cisco IOS XE Software startup configuration. An attacker could exploit this vulnerability by polling an affected device from a source address that should have been denied. A successful exploit could allow the att
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-05-07
Published