CVE-2025-20338: Medium severity Cisco IOS XE Software vulnerability
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with administrative privileges to execute arbitrary commands as root on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of user arguments that are passed to specific CLI commands. An attacker could exploit this vulnerability by logging in to the device CLI with valid administrative (level 15) credentials and using crafted commands at the CLI prompt. A successful exploit could allow the attacker to execute arbitrary commands as root.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20338?
CVE-2025-20338 is classified as a high severity vulnerability due to its potential to allow arbitrary command execution as root.
How do I fix CVE-2025-20338?
To remediate CVE-2025-20338, update your Cisco IOS XE Software to the latest version that addresses this vulnerability.
Who is affected by CVE-2025-20338?
CVE-2025-20338 affects devices running Cisco IOS XE Software with administrative privileges enabled.
What type of attack does CVE-2025-20338 allow?
CVE-2025-20338 allows authenticated local attackers to execute arbitrary commands on the underlying operating system.
Is user interaction required for CVE-2025-20338?
No, CVE-2025-20338 does not require user interaction, as it involves authenticated local access.