Article Details
Scrape Timestamp (UTC): 2025-09-24 17:00:30.276
Original Article Text
Click to Toggle View
Cisco warns of IOS zero-day vulnerability exploited in attacks. Cisco has released security updates to address a high-severity zero-day vulnerability in Cisco IOS and IOS XE Software that is currently being exploited in attacks. Tracked as CVE-2025-20352, the flaw is due to a stack-based buffer overflow weakness found in the Simple Network Management Protocol (SNMP) subsystem of vulnerable IOS and IOS XE software, impacting all devices with SNMP enabled. Authenticated, remote attackers with low privileges can exploit this vulnerability to trigger denial-of-service (DoS) conditions on unpatched devices. High-privileged attackers, on the other hand, can gain complete control of systems running vulnerable Cisco IOS XE software by executing code as the root user. "An attacker could exploit this vulnerability by sending a crafted SNMP packet to an affected device over IPv4 or IPv6 networks," Cisco said in a Wednesday advisory. "The Cisco Product Security Incident Response Team (PSIRT) became aware of successful exploitation of this vulnerability in the wild after local Administrator credentials were compromised. Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability." While there are no workarounds to address this vulnerability besides applying the patches released today, Cisco said that administrators who can't immediately upgrade the vulnerable software can temporarily mitigate the issue by limiting SNMP access on an affected system to trusted users. "To fully remediate this vulnerability and avoid future exposure as described in this advisory, Cisco strongly recommends that customers upgrade to the fixed software indicated in this advisory," the company warned. Today, Cisco patched 13 other security vulnerabilities, including two for which proof-of-concept exploit code is available. The first one, a Cisco IOS XE reflected cross-site scripting (XSS) flaw tracked as CVE-2025-20240, can be used by an unauthenticated, remote attacker to steal cookies from vulnerable devices. The second, tracked as CVE-2025-20149, is a denial-of-service vulnerability that allows authenticated, local attackers to force affected devices to reload. In May, the company also fixed a maximum severity IOS XE flaw impacting Wireless LAN Controllers, which enabled unauthenticated attackers to remotely take over devices using a hard-coded JSON Web Token (JWT). Picus Blue Report 2025 is Here: 2X increase in password cracking 46% of environments had passwords cracked, nearly doubling from 25% last year. Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.
Daily Brief Summary
Cisco has issued patches for a critical zero-day vulnerability, CVE-2025-20352, affecting IOS and IOS XE Software, currently being exploited in the wild.
The flaw resides in the SNMP subsystem, allowing authenticated attackers to trigger denial-of-service conditions or gain root access.
Exploitation involves sending crafted SNMP packets over IPv4 or IPv6 networks, with attacks observed following compromised administrator credentials.
Cisco advises immediate software upgrades to mitigate risks, as no workarounds exist beyond limiting SNMP access to trusted users.
In addition to the zero-day patch, Cisco addressed 13 other vulnerabilities, including an XSS flaw and a denial-of-service issue with available exploit code.
The urgency of patching is underscored by the potential for attackers to fully control affected systems, posing significant operational risks.
Organizations are encouraged to prioritize updates to prevent exploitation and maintain network security integrity.