CVE-2025-20172

A vulnerability in the SNMP subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affected device. For Cisco IOS and IOS XE Software, a successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition. For Cisco IOS XR Software, a successful exploit could allow the attacker to cause the SNMP process to restart, resulting in an interrupted SNMP response from an affected device. Devices that are running Cisco IOS XR Software will not reload.  This vulnerability affects SNMP versions 1, 2c, and 3. To exploit this vulnerability through SNMP v2c or earlier, the attacker must know a valid read-write or read-only SNMP community string for the affected system. To exploit this vulnerability through SNMP v3, the attacker must have valid SNMP user credentials for the affected system.

Published: 2025-02-05 Last update: 2025-07-03 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2025-20172 is rated Moderate Risk (49.8/100): CVSS High severity, with medium exploitation likelihood (EPSS 0.31%). Mandatory action: Review affected assets and schedule remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2025-20172

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-03-16 0.15% 0.31% +0.16%
2 2025-12-28 0.11% 0.15% +0.04%
3 2025-12-27 0.11%

Full EPSS history (9 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2025-20172

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
7.7 3.1 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:L)
A normal user session is enough; they don’t have to be admin.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:C)
Breaking this can reach past the original component and bite other resources—bigger blast radius.
Confidentiality (C:N)
Doesn’t really leak secrets in a meaningful way.
Integrity (I:N)
Data isn’t meaningfully altered or forged.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
3.1 4.0 [email protected]

Weakness enumeration for CVE-2025-20172

Affected software / configurations for CVE-2025-20172

Vendor Product Version Raw CPE
cisco ios 12.2\(33\)sre cpe:2.3:o:cisco:ios:12.2\(33\)sre:*:*:*:*:*:*:*
cisco ios 12.2\(33\)sre0a cpe:2.3:o:cisco:ios:12.2\(33\)sre0a:*:*:*:*:*:*:*
cisco ios 12.2\(33\)sre1 cpe:2.3:o:cisco:ios:12.2\(33\)sre1:*:*:*:*:*:*:*
cisco ios 12.2\(33\)sre2 cpe:2.3:o:cisco:ios:12.2\(33\)sre2:*:*:*:*:*:*:*
cisco ios 12.2\(33\)sre3 cpe:2.3:o:cisco:ios:12.2\(33\)sre3:*:*:*:*:*:*:*
cisco ios 12.2\(33\)sre4 cpe:2.3:o:cisco:ios:12.2\(33\)sre4:*:*:*:*:*:*:*
cisco ios 12.2\(33\)sre5 cpe:2.3:o:cisco:ios:12.2\(33\)sre5:*:*:*:*:*:*:*
cisco ios 12.2\(33\)sre6 cpe:2.3:o:cisco:ios:12.2\(33\)sre6:*:*:*:*:*:*:*
cisco ios 12.2\(33\)sre7 cpe:2.3:o:cisco:ios:12.2\(33\)sre7:*:*:*:*:*:*:*
cisco ios 12.2\(33\)sre7a cpe:2.3:o:cisco:ios:12.2\(33\)sre7a:*:*:*:*:*:*:*
cisco ios 12.2\(33\)sre8 cpe:2.3:o:cisco:ios:12.2\(33\)sre8:*:*:*:*:*:*:*
cisco ios 12.2\(33\)sre9 cpe:2.3:o:cisco:ios:12.2\(33\)sre9:*:*:*:*:*:*:*
cisco ios 12.2\(33\)sre9a cpe:2.3:o:cisco:ios:12.2\(33\)sre9a:*:*:*:*:*:*:*
cisco ios 12.2\(33\)sre10 cpe:2.3:o:cisco:ios:12.2\(33\)sre10:*:*:*:*:*:*:*
cisco ios 12.2\(33\)sre11 cpe:2.3:o:cisco:ios:12.2\(33\)sre11:*:*:*:*:*:*:*
cisco ios 12.2\(33\)sre12 cpe:2.3:o:cisco:ios:12.2\(33\)sre12:*:*:*:*:*:*:*
cisco ios 12.2\(33\)sre13 cpe:2.3:o:cisco:ios:12.2\(33\)sre13:*:*:*:*:*:*:*
cisco ios 12.2\(33\)sre14 cpe:2.3:o:cisco:ios:12.2\(33\)sre14:*:*:*:*:*:*:*
cisco ios 12.2\(33\)sre15 cpe:2.3:o:cisco:ios:12.2\(33\)sre15:*:*:*:*:*:*:*
cisco ios 12.2\(33\)sre15a cpe:2.3:o:cisco:ios:12.2\(33\)sre15a:*:*:*:*:*:*:*
cisco ios 15.0\(1\)ex cpe:2.3:o:cisco:ios:15.0\(1\)ex:*:*:*:*:*:*:*
cisco ios 15.0\(1\)mr cpe:2.3:o:cisco:ios:15.0\(1\)mr:*:*:*:*:*:*:*
cisco ios 15.0\(1\)s cpe:2.3:o:cisco:ios:15.0\(1\)s:*:*:*:*:*:*:*
cisco ios 15.0\(1\)s1 cpe:2.3:o:cisco:ios:15.0\(1\)s1:*:*:*:*:*:*:*
cisco ios 15.0\(1\)s2 cpe:2.3:o:cisco:ios:15.0\(1\)s2:*:*:*:*:*:*:*
cisco ios 15.0\(1\)s3a cpe:2.3:o:cisco:ios:15.0\(1\)s3a:*:*:*:*:*:*:*
cisco ios 15.0\(1\)s4 cpe:2.3:o:cisco:ios:15.0\(1\)s4:*:*:*:*:*:*:*
cisco ios 15.0\(1\)s4a cpe:2.3:o:cisco:ios:15.0\(1\)s4a:*:*:*:*:*:*:*
cisco ios 15.0\(1\)s5 cpe:2.3:o:cisco:ios:15.0\(1\)s5:*:*:*:*:*:*:*
cisco ios 15.0\(1\)s6 cpe:2.3:o:cisco:ios:15.0\(1\)s6:*:*:*:*:*:*:*
cisco ios 15.0\(2\)ea cpe:2.3:o:cisco:ios:15.0\(2\)ea:*:*:*:*:*:*:*
cisco ios 15.0\(2\)ea1 cpe:2.3:o:cisco:ios:15.0\(2\)ea1:*:*:*:*:*:*:*
cisco ios 15.0\(2\)ej cpe:2.3:o:cisco:ios:15.0\(2\)ej:*:*:*:*:*:*:*
cisco ios 15.0\(2\)ej1 cpe:2.3:o:cisco:ios:15.0\(2\)ej1:*:*:*:*:*:*:*
cisco ios 15.0\(2\)ek cpe:2.3:o:cisco:ios:15.0\(2\)ek:*:*:*:*:*:*:*
cisco ios 15.0\(2\)ek1 cpe:2.3:o:cisco:ios:15.0\(2\)ek1:*:*:*:*:*:*:*
cisco ios 15.0\(2\)ex cpe:2.3:o:cisco:ios:15.0\(2\)ex:*:*:*:*:*:*:*
cisco ios 15.0\(2\)ex1 cpe:2.3:o:cisco:ios:15.0\(2\)ex1:*:*:*:*:*:*:*
cisco ios 15.0\(2\)ex2 cpe:2.3:o:cisco:ios:15.0\(2\)ex2:*:*:*:*:*:*:*
cisco ios 15.0\(2\)ex3 cpe:2.3:o:cisco:ios:15.0\(2\)ex3:*:*:*:*:*:*:*
cisco ios 15.0\(2\)ex4 cpe:2.3:o:cisco:ios:15.0\(2\)ex4:*:*:*:*:*:*:*
cisco ios 15.0\(2\)ex5 cpe:2.3:o:cisco:ios:15.0\(2\)ex5:*:*:*:*:*:*:*
cisco ios 15.0\(2\)ex8 cpe:2.3:o:cisco:ios:15.0\(2\)ex8:*:*:*:*:*:*:*
cisco ios 15.0\(2\)ex10 cpe:2.3:o:cisco:ios:15.0\(2\)ex10:*:*:*:*:*:*:*
cisco ios 15.0\(2\)ex11 cpe:2.3:o:cisco:ios:15.0\(2\)ex11:*:*:*:*:*:*:*
cisco ios 15.0\(2\)ex12 cpe:2.3:o:cisco:ios:15.0\(2\)ex12:*:*:*:*:*:*:*
cisco ios 15.0\(2\)ex13 cpe:2.3:o:cisco:ios:15.0\(2\)ex13:*:*:*:*:*:*:*
cisco ios 15.0\(2\)ey cpe:2.3:o:cisco:ios:15.0\(2\)ey:*:*:*:*:*:*:*
cisco ios 15.0\(2\)ey1 cpe:2.3:o:cisco:ios:15.0\(2\)ey1:*:*:*:*:*:*:*
cisco ios 15.0\(2\)ey2 cpe:2.3:o:cisco:ios:15.0\(2\)ey2:*:*:*:*:*:*:*
cisco ios 15.0\(2\)ey3 cpe:2.3:o:cisco:ios:15.0\(2\)ey3:*:*:*:*:*:*:*
cisco ios 15.0\(2\)ez cpe:2.3:o:cisco:ios:15.0\(2\)ez:*:*:*:*:*:*:*
cisco ios 15.0\(2\)mr cpe:2.3:o:cisco:ios:15.0\(2\)mr:*:*:*:*:*:*:*
cisco ios 15.0\(2\)se cpe:2.3:o:cisco:ios:15.0\(2\)se:*:*:*:*:*:*:*
cisco ios 15.0\(2\)se1 cpe:2.3:o:cisco:ios:15.0\(2\)se1:*:*:*:*:*:*:*
cisco ios 15.0\(2\)se2 cpe:2.3:o:cisco:ios:15.0\(2\)se2:*:*:*:*:*:*:*
cisco ios 15.0\(2\)se3 cpe:2.3:o:cisco:ios:15.0\(2\)se3:*:*:*:*:*:*:*
cisco ios 15.0\(2\)se4 cpe:2.3:o:cisco:ios:15.0\(2\)se4:*:*:*:*:*:*:*
cisco ios 15.0\(2\)se5 cpe:2.3:o:cisco:ios:15.0\(2\)se5:*:*:*:*:*:*:*
cisco ios 15.0\(2\)se6 cpe:2.3:o:cisco:ios:15.0\(2\)se6:*:*:*:*:*:*:*
cisco ios 15.0\(2\)se7 cpe:2.3:o:cisco:ios:15.0\(2\)se7:*:*:*:*:*:*:*
cisco ios 15.0\(2\)se8 cpe:2.3:o:cisco:ios:15.0\(2\)se8:*:*:*:*:*:*:*
cisco ios 15.0\(2\)se9 cpe:2.3:o:cisco:ios:15.0\(2\)se9:*:*:*:*:*:*:*
cisco ios 15.0\(2\)se10 cpe:2.3:o:cisco:ios:15.0\(2\)se10:*:*:*:*:*:*:*
cisco ios 15.0\(2\)se10a cpe:2.3:o:cisco:ios:15.0\(2\)se10a:*:*:*:*:*:*:*
cisco ios 15.0\(2\)se11 cpe:2.3:o:cisco:ios:15.0\(2\)se11:*:*:*:*:*:*:*
cisco ios 15.0\(2\)se12 cpe:2.3:o:cisco:ios:15.0\(2\)se12:*:*:*:*:*:*:*
cisco ios 15.0\(2\)se13 cpe:2.3:o:cisco:ios:15.0\(2\)se13:*:*:*:*:*:*:*
cisco ios 15.0\(2a\)ex5 cpe:2.3:o:cisco:ios:15.0\(2a\)ex5:*:*:*:*:*:*:*
cisco ios 15.1\(1\)s cpe:2.3:o:cisco:ios:15.1\(1\)s:*:*:*:*:*:*:*
cisco ios 15.1\(1\)s1 cpe:2.3:o:cisco:ios:15.1\(1\)s1:*:*:*:*:*:*:*
cisco ios 15.1\(1\)s2 cpe:2.3:o:cisco:ios:15.1\(1\)s2:*:*:*:*:*:*:*
cisco ios 15.1\(1\)sg cpe:2.3:o:cisco:ios:15.1\(1\)sg:*:*:*:*:*:*:*
cisco ios 15.1\(1\)sg1 cpe:2.3:o:cisco:ios:15.1\(1\)sg1:*:*:*:*:*:*:*
cisco ios 15.1\(1\)sg2 cpe:2.3:o:cisco:ios:15.1\(1\)sg2:*:*:*:*:*:*:*
cisco ios 15.1\(2\)s cpe:2.3:o:cisco:ios:15.1\(2\)s:*:*:*:*:*:*:*
cisco ios 15.1\(2\)s1 cpe:2.3:o:cisco:ios:15.1\(2\)s1:*:*:*:*:*:*:*
cisco ios 15.1\(2\)s2 cpe:2.3:o:cisco:ios:15.1\(2\)s2:*:*:*:*:*:*:*
cisco ios 15.1\(2\)sg cpe:2.3:o:cisco:ios:15.1\(2\)sg:*:*:*:*:*:*:*
cisco ios 15.1\(2\)sg1 cpe:2.3:o:cisco:ios:15.1\(2\)sg1:*:*:*:*:*:*:*

References for CVE-2025-20172

cvelogic Threat Intelligence