CVE-2025-20170

A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition.  This vulnerability affects SNMP versions 1, 2c, and 3. To exploit this vulnerability through SNMP v2c or earlier, the attacker must know a valid read-write or read-only SNMP community string for the affected system. To exploit this vulnerability through SNMP v3, the attacker must have valid SNMP user credentials for the affected system.

Published: 2025-02-05 Last update: 2025-07-03 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2025-20170 is rated Moderate Risk (53.2/100): CVSS High severity, with medium exploitation likelihood (EPSS 0.46%). Mandatory action: Review affected assets and schedule remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2025-20170

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-03-16 0.37% 0.46% +0.09%
2 2025-12-28 0.27% 0.37% +0.10%
3 2025-12-27 0.27%

Full EPSS history (13 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2025-20170

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
7.7 3.1 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:L)
A normal user session is enough; they don’t have to be admin.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:C)
Breaking this can reach past the original component and bite other resources—bigger blast radius.
Confidentiality (C:N)
Doesn’t really leak secrets in a meaningful way.
Integrity (I:N)
Data isn’t meaningfully altered or forged.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
3.1 4.0 [email protected]

Weakness enumeration for CVE-2025-20170

Affected software / configurations for CVE-2025-20170

Vendor Product Version Raw CPE
cisco ios 12.2\(1\) cpe:2.3:o:cisco:ios:12.2\(1\):*:*:*:*:*:*:*
cisco ios 12.2\(1\)dx cpe:2.3:o:cisco:ios:12.2\(1\)dx:*:*:*:*:*:*:*
cisco ios 12.2\(1\)dx1 cpe:2.3:o:cisco:ios:12.2\(1\)dx1:*:*:*:*:*:*:*
cisco ios 12.2\(1\)m0 cpe:2.3:o:cisco:ios:12.2\(1\)m0:*:*:*:*:*:*:*
cisco ios 12.2\(1\)mb1 cpe:2.3:o:cisco:ios:12.2\(1\)mb1:*:*:*:*:*:*:*
cisco ios 12.2\(1\)xd cpe:2.3:o:cisco:ios:12.2\(1\)xd:*:*:*:*:*:*:*
cisco ios 12.2\(1\)xd1 cpe:2.3:o:cisco:ios:12.2\(1\)xd1:*:*:*:*:*:*:*
cisco ios 12.2\(1\)xd2 cpe:2.3:o:cisco:ios:12.2\(1\)xd2:*:*:*:*:*:*:*
cisco ios 12.2\(1\)xd3 cpe:2.3:o:cisco:ios:12.2\(1\)xd3:*:*:*:*:*:*:*
cisco ios 12.2\(1\)xd4 cpe:2.3:o:cisco:ios:12.2\(1\)xd4:*:*:*:*:*:*:*
cisco ios 12.2\(1\)xe cpe:2.3:o:cisco:ios:12.2\(1\)xe:*:*:*:*:*:*:*
cisco ios 12.2\(1\)xe1 cpe:2.3:o:cisco:ios:12.2\(1\)xe1:*:*:*:*:*:*:*
cisco ios 12.2\(1\)xe2 cpe:2.3:o:cisco:ios:12.2\(1\)xe2:*:*:*:*:*:*:*
cisco ios 12.2\(1\)xf cpe:2.3:o:cisco:ios:12.2\(1\)xf:*:*:*:*:*:*:*
cisco ios 12.2\(1\)xf1 cpe:2.3:o:cisco:ios:12.2\(1\)xf1:*:*:*:*:*:*:*
cisco ios 12.2\(1\)xs cpe:2.3:o:cisco:ios:12.2\(1\)xs:*:*:*:*:*:*:*
cisco ios 12.2\(1\)xs1a cpe:2.3:o:cisco:ios:12.2\(1\)xs1a:*:*:*:*:*:*:*
cisco ios 12.2\(1\)xs2 cpe:2.3:o:cisco:ios:12.2\(1\)xs2:*:*:*:*:*:*:*
cisco ios 12.2\(1a\) cpe:2.3:o:cisco:ios:12.2\(1a\):*:*:*:*:*:*:*
cisco ios 12.2\(1a\)xc cpe:2.3:o:cisco:ios:12.2\(1a\)xc:*:*:*:*:*:*:*
cisco ios 12.2\(1a\)xc1 cpe:2.3:o:cisco:ios:12.2\(1a\)xc1:*:*:*:*:*:*:*
cisco ios 12.2\(1a\)xc2 cpe:2.3:o:cisco:ios:12.2\(1a\)xc2:*:*:*:*:*:*:*
cisco ios 12.2\(1a\)xc3 cpe:2.3:o:cisco:ios:12.2\(1a\)xc3:*:*:*:*:*:*:*
cisco ios 12.2\(1b\) cpe:2.3:o:cisco:ios:12.2\(1b\):*:*:*:*:*:*:*
cisco ios 12.2\(1b\)da cpe:2.3:o:cisco:ios:12.2\(1b\)da:*:*:*:*:*:*:*
cisco ios 12.2\(1b\)da1 cpe:2.3:o:cisco:ios:12.2\(1b\)da1:*:*:*:*:*:*:*
cisco ios 12.2\(1c\) cpe:2.3:o:cisco:ios:12.2\(1c\):*:*:*:*:*:*:*
cisco ios 12.2\(1d\) cpe:2.3:o:cisco:ios:12.2\(1d\):*:*:*:*:*:*:*
cisco ios 12.2\(2\)b cpe:2.3:o:cisco:ios:12.2\(2\)b:*:*:*:*:*:*:*
cisco ios 12.2\(2\)b1 cpe:2.3:o:cisco:ios:12.2\(2\)b1:*:*:*:*:*:*:*
cisco ios 12.2\(2\)b2 cpe:2.3:o:cisco:ios:12.2\(2\)b2:*:*:*:*:*:*:*
cisco ios 12.2\(2\)b3 cpe:2.3:o:cisco:ios:12.2\(2\)b3:*:*:*:*:*:*:*
cisco ios 12.2\(2\)b4 cpe:2.3:o:cisco:ios:12.2\(2\)b4:*:*:*:*:*:*:*
cisco ios 12.2\(2\)b5 cpe:2.3:o:cisco:ios:12.2\(2\)b5:*:*:*:*:*:*:*
cisco ios 12.2\(2\)b6 cpe:2.3:o:cisco:ios:12.2\(2\)b6:*:*:*:*:*:*:*
cisco ios 12.2\(2\)b7 cpe:2.3:o:cisco:ios:12.2\(2\)b7:*:*:*:*:*:*:*
cisco ios 12.2\(2\)bx cpe:2.3:o:cisco:ios:12.2\(2\)bx:*:*:*:*:*:*:*
cisco ios 12.2\(2\)bx1 cpe:2.3:o:cisco:ios:12.2\(2\)bx1:*:*:*:*:*:*:*
cisco ios 12.2\(2\)by cpe:2.3:o:cisco:ios:12.2\(2\)by:*:*:*:*:*:*:*
cisco ios 12.2\(2\)by1 cpe:2.3:o:cisco:ios:12.2\(2\)by1:*:*:*:*:*:*:*
cisco ios 12.2\(2\)by2 cpe:2.3:o:cisco:ios:12.2\(2\)by2:*:*:*:*:*:*:*
cisco ios 12.2\(2\)by3 cpe:2.3:o:cisco:ios:12.2\(2\)by3:*:*:*:*:*:*:*
cisco ios 12.2\(2\)dd cpe:2.3:o:cisco:ios:12.2\(2\)dd:*:*:*:*:*:*:*
cisco ios 12.2\(2\)dd1 cpe:2.3:o:cisco:ios:12.2\(2\)dd1:*:*:*:*:*:*:*
cisco ios 12.2\(2\)dd2 cpe:2.3:o:cisco:ios:12.2\(2\)dd2:*:*:*:*:*:*:*
cisco ios 12.2\(2\)dd3 cpe:2.3:o:cisco:ios:12.2\(2\)dd3:*:*:*:*:*:*:*
cisco ios 12.2\(2\)dd4 cpe:2.3:o:cisco:ios:12.2\(2\)dd4:*:*:*:*:*:*:*
cisco ios 12.2\(2\)dx3 cpe:2.3:o:cisco:ios:12.2\(2\)dx3:*:*:*:*:*:*:*
cisco ios 12.2\(2\)xa cpe:2.3:o:cisco:ios:12.2\(2\)xa:*:*:*:*:*:*:*
cisco ios 12.2\(2\)xa1 cpe:2.3:o:cisco:ios:12.2\(2\)xa1:*:*:*:*:*:*:*
cisco ios 12.2\(2\)xa2 cpe:2.3:o:cisco:ios:12.2\(2\)xa2:*:*:*:*:*:*:*
cisco ios 12.2\(2\)xa3 cpe:2.3:o:cisco:ios:12.2\(2\)xa3:*:*:*:*:*:*:*
cisco ios 12.2\(2\)xa4 cpe:2.3:o:cisco:ios:12.2\(2\)xa4:*:*:*:*:*:*:*
cisco ios 12.2\(2\)xa5 cpe:2.3:o:cisco:ios:12.2\(2\)xa5:*:*:*:*:*:*:*
cisco ios 12.2\(2\)xb1 cpe:2.3:o:cisco:ios:12.2\(2\)xb1:*:*:*:*:*:*:*
cisco ios 12.2\(2\)xb2 cpe:2.3:o:cisco:ios:12.2\(2\)xb2:*:*:*:*:*:*:*
cisco ios 12.2\(2\)xb3 cpe:2.3:o:cisco:ios:12.2\(2\)xb3:*:*:*:*:*:*:*
cisco ios 12.2\(2\)xb5 cpe:2.3:o:cisco:ios:12.2\(2\)xb5:*:*:*:*:*:*:*
cisco ios 12.2\(2\)xb6 cpe:2.3:o:cisco:ios:12.2\(2\)xb6:*:*:*:*:*:*:*
cisco ios 12.2\(2\)xb7 cpe:2.3:o:cisco:ios:12.2\(2\)xb7:*:*:*:*:*:*:*
cisco ios 12.2\(2\)xb8 cpe:2.3:o:cisco:ios:12.2\(2\)xb8:*:*:*:*:*:*:*
cisco ios 12.2\(2\)xb10 cpe:2.3:o:cisco:ios:12.2\(2\)xb10:*:*:*:*:*:*:*
cisco ios 12.2\(2\)xb11 cpe:2.3:o:cisco:ios:12.2\(2\)xb11:*:*:*:*:*:*:*
cisco ios 12.2\(2\)xb12 cpe:2.3:o:cisco:ios:12.2\(2\)xb12:*:*:*:*:*:*:*
cisco ios 12.2\(2\)xb14 cpe:2.3:o:cisco:ios:12.2\(2\)xb14:*:*:*:*:*:*:*
cisco ios 12.2\(2\)xb15 cpe:2.3:o:cisco:ios:12.2\(2\)xb15:*:*:*:*:*:*:*
cisco ios 12.2\(2\)xc cpe:2.3:o:cisco:ios:12.2\(2\)xc:*:*:*:*:*:*:*
cisco ios 12.2\(2\)xc1 cpe:2.3:o:cisco:ios:12.2\(2\)xc1:*:*:*:*:*:*:*
cisco ios 12.2\(2\)xc2 cpe:2.3:o:cisco:ios:12.2\(2\)xc2:*:*:*:*:*:*:*
cisco ios 12.2\(2\)xf cpe:2.3:o:cisco:ios:12.2\(2\)xf:*:*:*:*:*:*:*
cisco ios 12.2\(2\)xf1 cpe:2.3:o:cisco:ios:12.2\(2\)xf1:*:*:*:*:*:*:*
cisco ios 12.2\(2\)xf2 cpe:2.3:o:cisco:ios:12.2\(2\)xf2:*:*:*:*:*:*:*
cisco ios 12.2\(2\)xg cpe:2.3:o:cisco:ios:12.2\(2\)xg:*:*:*:*:*:*:*
cisco ios 12.2\(2\)xh cpe:2.3:o:cisco:ios:12.2\(2\)xh:*:*:*:*:*:*:*
cisco ios 12.2\(2\)xh1 cpe:2.3:o:cisco:ios:12.2\(2\)xh1:*:*:*:*:*:*:*
cisco ios 12.2\(2\)xh2 cpe:2.3:o:cisco:ios:12.2\(2\)xh2:*:*:*:*:*:*:*
cisco ios 12.2\(2\)xi cpe:2.3:o:cisco:ios:12.2\(2\)xi:*:*:*:*:*:*:*
cisco ios 12.2\(2\)xi1 cpe:2.3:o:cisco:ios:12.2\(2\)xi1:*:*:*:*:*:*:*
cisco ios 12.2\(2\)xi2 cpe:2.3:o:cisco:ios:12.2\(2\)xi2:*:*:*:*:*:*:*
cisco ios 12.2\(2\)xj cpe:2.3:o:cisco:ios:12.2\(2\)xj:*:*:*:*:*:*:*

References for CVE-2025-20170

cvelogic Threat Intelligence