CVE-2025-20352
Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability
- 대응 우선순위
- 최우선
- CVSS
- 7.7
- EPSS
- 37.6% 백분위 98.3% · 2026.06.27 기준
- CISA KEV
- 등록
- 조치 기한
- 2025.10.20
- 공개일
- 2025.09.25
CISA KEV에 등록된 실제 악용 확인 취약점
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following: An authenticated, remote attacker with low privileges could cause a denial of service (DoS) condition on an affected device that is running Cisco IOS Software or Cisco IOS XE Software. To cause the DoS, the attacker must have the SNMPv2c or earlier read-only community string or valid SNMPv3 user credentials. An authenticated, remote attacker with high privileges could execute code as the root user on an affected device that is running Cisco IO...
공급사 Cisco
제품 IOS and IOS XE
영향 버전 12.2(55)SE, 12.2(55)SE3, 12.2(55)SE2, 12.2(58)SE, 12.2(55)SE1, 12.2(58)SE1, 12.2(55)SE4, 12.2(58)SE2, 12.2(55)SE5, 12.2(55)SE6, 12.2(55)SE7, 12.2(55)SE8, 12.2(55)SE9, 12.2(55)SE10, 12.2(55)SE11, 12.2(55)SE12, 12.2(55)SE13, 12.2(58)EZ, 12.2(53)EZ, 12.2(55)EZ
수정 버전 공식 출처에서 확인 필요
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
조치 기한: 2025.10.20CVSS 벡터 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
CWE CWE-121
KEV 등록일 2025.09.29
랜섬웨어 캠페인 사용 미확인
CISA 비고 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snmp-x4LPhte ; https://nvd.nist.gov/vuln/detail/CVE-2025-20352
EPSS 데이터 기준일 2026.06.27