CVE-2025-20160: High severity Cisco IOS Software vulnerability
A vulnerability in the implementation of the TACACS+ protocol in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to view sensitive data or bypass authentication. This vulnerability exists because the system does not properly check whether the required TACACS+ shared secret is configured. A machine-in-the-middle attacker could exploit this vulnerability by intercepting and reading unencrypted TACACS+ messages or impersonating the TACACS+ server and falsely accepting arbitrary authentication requests. A successful exploit could allow the attacker to view sensitive information in a TACACS+ message or bypass authentication and gain access to the affected device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20160?
CVE-2025-20160 has a critical severity rating due to its potential to allow remote attackers to bypass authentication.
How do I fix CVE-2025-20160?
To fix CVE-2025-20160, update your Cisco IOS or IOS XE software to the latest fixed version provided by Cisco.
Who is affected by CVE-2025-20160?
Organizations using Cisco IOS Software and Cisco IOS XE Software are affected by CVE-2025-20160.
What type of attack is possible with CVE-2025-20160?
CVE-2025-20160 allows an unauthenticated remote attacker to view sensitive data or bypass authentication.
When was CVE-2025-20160 disclosed?
CVE-2025-20160 was disclosed on the date it was identified in early 2025.