CVE-2025-20149: Buffer Overflow
A vulnerability in the CLI of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to a buffer overflow. An attacker with a low-privileged account could exploit this vulnerability by using crafted commands at the CLI prompt. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20149?
CVE-2025-20149 has a severity rating that indicates it can lead to a denial of service (DoS) condition.
How do I fix CVE-2025-20149?
To fix CVE-2025-20149, you should apply the latest patches and updates provided by Cisco for affected IOS and IOS XE Software.
Who is affected by CVE-2025-20149?
CVE-2025-20149 affects users of Cisco IOS Software and Cisco IOS XE Software with authenticated local access.
What type of attack does CVE-2025-20149 facilitate?
CVE-2025-20149 facilitates a buffer overflow attack which can cause the device to reload unexpectedly.
What are the consequences of exploiting CVE-2025-20149?
Exploiting CVE-2025-20149 can result in a denial of service (DoS) condition on affected devices.