CVE-2025-20151
MEDIUMDescription
A vulnerability in the implementation of the Simple Network Management Protocol Version 3 (SNMPv3) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to poll an affected device using SNMP, even if the device is configured to deny SNMP traffic from an unauthorized source or the SNMPv3 username is removed from the configuration. This vulnerability exists because of the way that the SNMPv3 configuration is stored in the Cisco IOS Software and Cisco IOS XE Software startup configuration. An attacker could exploit this vulnerability by polling an affected device from a source address that should have been denied. A successful exploit could allow the attacker to perform SNMP operations from a source that should be denied. Note: The attacker has no control of the SNMPv3 configuration. To exploit this vulnerability, the attacker must have valid SNMPv3 user credentials. For more information, see the section of this advisory.
Is your site exposed to CVE-2025-20151?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| cisco | ios_xe_sd-wan |
| cisco | ios_xe_sd-wan |
| cisco | ios_xe_sd-wan |
| cisco | ios_xe_sd-wan |
| cisco | ios_xe_sd-wan |
| cisco | ios_xe_sd-wan |
| cisco | ios_xe_sd-wan |
| cisco | ios_xe_sd-wan |
| cisco | ios_xe_sd-wan |
| cisco | ios_xe_sd-wan |
| cisco | ios_xe_sd-wan |
| cisco | ios_xe_sd-wan |
| cisco | ios_xe_sd-wan |
| cisco | ios_xe_sd-wan |
| cisco | ios_xe_sd-wan |
| cisco | ios_xe_sd-wan |
| cisco | ios_xe_sd-wan |
| cisco | ios_xe_sd-wan |
| cisco | ios_xe_sd-wan |
| cisco | ios_xe_sd-wan |
| cisco | ios_xe_sd-wan |
| cisco | ios_xe_sd-wan |
| cisco | ios_xe_sd-wan |
| cisco | ios_xe_sd-wan |
| cisco | ios_xe_sd-wan |
| cisco | ios_xe_sd-wan |
| cisco | ios_xe_sd-wan |
| cisco | ios_xe_sd-wan |
| cisco | ios_xe_sd-wan |
| cisco | ios_xe_sd-wan |
References
Frequently Asked Questions
What is CVE-2025-20151? +
How severe is CVE-2025-20151? +
What products are affected by CVE-2025-20151? +
How do I check if I'm vulnerable to CVE-2025-20151? +
Related Vulnerabilities
Wrong configuration in Touch Pal application can collect user behavior data without awareness by the user.
In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage this vulnerability to execute code in the …
Busybox 1.31.1 - Multiple Known Vulnerabilities.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
Permission verification vulnerability in the wpa_supplicant module Impact: Successful exploitation of this vulnerability will affect availability.
Access permission verification vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Transient DOS in WLAN Host and Firmware when large number of open authentication frames are sent with an invalid transaction …