CVE-2025-20191: Multiple Cisco Products Denial of Service Vulnerability
A vulnerability in the Switch Integrated Security Features (SISF) of Cisco IOS Software, Cisco IOS XE Software, Cisco NX-OS Software, and Cisco Wireless LAN Controller (WLC) AireOS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to the incorrect handling of DHCPv6 packets. An attacker could exploit this vulnerability by sending a crafted DHCPv6 packet to an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20191?
The severity of CVE-2025-20191 is high, as it can allow an unauthenticated attacker to cause a denial of service.
How do I fix CVE-2025-20191?
To fix CVE-2025-20191, update the affected Cisco software to the latest version provided by Cisco.
Which Cisco software is affected by CVE-2025-20191?
CVE-2025-20191 affects Cisco IOS Software, Cisco IOS XE Software, Cisco NX-OS Software, and Cisco Wireless LAN Controller AireOS Software.
What impact does CVE-2025-20191 have on network devices?
CVE-2025-20191 can lead to a denial of service condition, potentially disrupting network operations.
Is there a workaround to mitigate CVE-2025-20191?
Currently, the best mitigation for CVE-2025-20191 is to apply available software updates from Cisco.