CVE-2025-20155 describes a vulnerability in Cisco IOS XE Software's bootstrap loading process, specifically affecting devices configured for SD-WAN or SD-Routing. This flaw, stemming from insufficient input validation of bootstrap files, allows an authenticated, local attacker with high privileges to write arbitrary files to the underlying operating system. The vulnerability carries a CVSS score of 6.0 (Medium), indicating a local attack vector with low complexity, requiring high privileges, and resulting in high impact to confidentiality and integrity. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
17.9.4CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:17.9.4:*:*:*:*:*:*:* | ||
17.9.4aCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:17.9.4a:*:*:*:*:*:*:* | ||
17.9.5CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:17.9.5:*:*:*:*:*:*:* | ||
17.9.5aCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:17.9.5a:*:*:*:*:*:*:* | ||
17.9.5bCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:17.9.5b:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.