cbcvebase.
CVE-2025-20352
published 2025-09-24

CVE-2025-20352: A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following: An…

PriorityP184high7.7CVSS 3.1
AVNACLPRLUINSCCNINAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2025-10-20
Exploited in the wild
EPSS
37.61%
98.4th percentile
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following: An authenticated, remote attacker with low privileges could cause a denial of service (DoS) condition on an affected device that is running Cisco IOS Software or Cisco IOS XE Software. To cause the DoS, the attacker must have the SNMPv2c or earlier read-only community string or valid SNMPv3 user credentials. An authenticated, remote attacker with high privileges could execute code as the root user on an affected device that is running Cisco IOS XE Software. To execute code as the root user, the attacker must have the SNMPv1 or v2c read-only community string or valid SNMPv3 user credentials and administrative or privilege 15 credentials on the affected device. An attacker could exploit this vulnerability by sending a crafted SNMP packet to an affected device over IPv4 or IPv6 networks. This vulnerability is due to a stack overflow condition in the SNMP subsystem of the affected software. A successful exploit could allow a low-privileged attacker to cause the affected system to reload, resulting in a DoS condition, or allow a high-privileged attacker to execute arbitrary code as the root user and obtain full control of the affected system. Note: This vulnerability affects all versions of SNMP.

Affected

2193 ranges· showing 25
VendorProductVersion rangeFixed in
ciscocisco_ios_xe_catalyst_sd-wan
ciscocisco_ios_xe_catalyst_sd-wan
ciscocisco_ios_xe_catalyst_sd-wan
ciscocisco_ios_xe_catalyst_sd-wan
ciscocisco_ios_xe_catalyst_sd-wan
ciscocisco_ios_xe_catalyst_sd-wan
ciscocisco_ios_xe_catalyst_sd-wan
ciscocisco_ios_xe_catalyst_sd-wan
ciscocisco_ios_xe_catalyst_sd-wan
ciscocisco_ios_xe_catalyst_sd-wan
ciscocisco_ios_xe_catalyst_sd-wan
ciscocisco_ios_xe_catalyst_sd-wan
ciscocisco_ios_xe_catalyst_sd-wan
ciscocisco_ios_xe_catalyst_sd-wan
ciscocisco_ios_xe_catalyst_sd-wan
ciscocisco_ios_xe_catalyst_sd-wan
ciscocisco_ios_xe_catalyst_sd-wan
ciscocisco_ios_xe_catalyst_sd-wan
ciscocisco_ios_xe_catalyst_sd-wan
ciscocisco_ios_xe_catalyst_sd-wan
ciscocisco_ios_xe_catalyst_sd-wan
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software

Detection & IOCsextracted from sources · hover to see the quote

otherdg3y8dpk
otherdg4y8epk
otherdg5y8fpk
otherdg6y8gpk
otherdg7y8hpk
otherCiscoEMX-1
otherCiscoEMX-2
otherCiscoEMX-3
otherCiscoEMX-4
otherCiscoEMX-5
otherEnaQWklg0
otherEnaQWklg1
otherEnaQWklg2
  • Hunt for hidden rogue account names matching the pattern dg[3-7]y8[d-h]pk in Cisco device running-config or AAA user databases — these are rootkit-concealed backdoor accounts planted by Operation Zero Disco.
  • Alert on the presence of EEM scripts named CiscoEMX-1 through CiscoEMX-5 in Cisco device configuration — these are rootkit-hidden persistence scripts.
  • Alert on ACLs named EnaQWklg0, EnaQWklg1, or EnaQWklg2 appearing in Cisco device configuration — these are rootkit-hidden ACLs used by the attacker.
  • Detect crafted SNMP packets containing shell command fragments (e.g., '$(ps -a') — the exploit splits OS commands across multiple SNMP packets due to per-packet byte limits.
  • Monitor for unexpected UDP traffic to any port on Cisco switch management IPs — the rootkit acts as a UDP listener on any port, including closed ones, for C2 communication.
  • Detect sudden zeroing of SNMP/syslog history buffer size on Cisco devices — the rootkit disables logging by setting the log size to zero to evade detection.
  • Alert on unexpected changes to the last running-config write timestamp on Cisco devices — the rootkit resets this timestamp to hide configuration modifications.
  • Look for a Linux ELF binary running inside Cisco guest shell performing ARP spoofing — this tool is used to impersonate waystation IPs and bypass internal firewalls.
  • Correlate exploitation attempts against Cisco SNMP (UDP/161) with subsequent Telnet (TCP/23) traffic to the same device — attackers chained CVE-2025-20352 with a modified CVE-2017-3881 Telnet exploit for memory read/write.
  • ·64-bit SNMP RCE rootkit installation requires the attacker to be able to run guest shell on the Cisco device at privilege level 15; 32-bit (3750G) exploitation does not require guest shell.
  • ·Rootkit components are fileless and volatile — hooks installed into IOSd memory disappear after a reboot, making post-reboot forensics unreliable without low-level firmware/ROM analysis.
  • ·Newer Cisco switch models (9400/9300 series) have ASLR which reduces but does not eliminate exploit success — repeated attempts can still succeed.
  • ·There is currently no universal automated tool to reliably determine whether a Cisco switch has been compromised by this operation; low-level firmware and ROM region investigation is required.
  • ·The rootkit's config-hiding feature (account names, EEM scripts, ACLs) is disabled by default and must be explicitly enabled by the attacker via the UDP C2 channel — absence of hidden items does not confirm a clean device.

CVSS provenance

nvdv3.17.7HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
vulncheck7.7HIGH
cisa7.7HIGH
vendor_cisco7.7HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.