CVE-2025-20172 is a denial-of-service vulnerability in the SNMP subsystem of Cisco IOS, IOS XE, and IOS XR Software, stemming from improper error handling of crafted SNMP requests. An authenticated, remote attacker can exploit this to cause unexpected device reloads in IOS/IOS XE or SNMP process restarts in IOS XR. The vulnerability has a CVSS score of 7.7 (HIGH), requiring valid SNMP community strings or user credentials for exploitation. There is currently no evidence of active exploitation, public exploit code, or significant community discussion regarding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.2\(33\)sreCPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.2\(33\)sre:*:*:*:*:*:*:* | ||
12.2\(33\)sre0aCPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.2\(33\)sre0a:*:*:*:*:*:*:* | ||
12.2\(33\)sre1CPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.2\(33\)sre1:*:*:*:*:*:*:* | ||
12.2\(33\)sre2CPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.2\(33\)sre2:*:*:*:*:*:*:* | ||
12.2\(33\)sre3CPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.2\(33\)sre3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.