HomeSecurityMultiple vulnerabilities in Cisco SNMP allow DoS attacks

Multiple vulnerabilities in Cisco SNMP allow DoS attacks

Cisco has announced the existence of multiple high-severity vulnerabilities in the Simple Network Management Protocol (SNMP) subsystem of IOS, IOS XE, and IOS XR software . The SNMP vulnerabilities could allow authenticated, remote attackers to conduct DoS attacks on affected devices .

See also: Vulnerability in Facebook Messenger on iOS allows DoS attack via emoji

SNMP DoS attacks

The vulnerabilities are identified as CVE-2025-20169, CVE-2025-20170 , and CVE-2025-20171, with a base score of 7.7 on the Common Vulnerability Scoring System (CVSS), indicating a high level of risk.

Vulnerabilities CVE-2025-20169, CVE-2025-20170, and CVE-2025-20171, located in the SNMP subsystem of Cisco IOS and Cisco IOS XE software, could allow a remotely authenticated attacker to conduct Denial of Service (DoS) attacks on vulnerable devices.

These vulnerabilities arise from inadequate error handling when processing SNMP requests. An attacker could exploit this vulnerability by submitting a maliciously crafted SNMP request to a vulnerable device.

See also: Vulnerability in Apache Tomcat allows Dos attacks

These issues affect all versions of SNMP—v1, v2c , and v3. To exploit these flaws, attackers must have valid access information. Specifically, for SNMP v2c and earlier versions, valid community strings with read-write or read-only permissions are required. In the case of SNMP v3, attackers need valid credentials to gain access.

Multiple vulnerabilities in Cisco SNMP allow DoS attacks

Cisco credits security researcher “leg00m,” who works with the Trend Micro Zero Day Initiative, for identifying and reporting these critical issues.

Devices , or IOS XR Software with SNMP enabled are at risk of DoS attacks from the vulnerabilities.

Cisco has stated that there are no workarounds for these vulnerabilities, but has suggested mitigations:

  • Restrict SNMP access to trusted devices only.
  • Disable vulnerable object identifiers (OIDs) where possible.

Cisco is actively working on software updates to address these flaws.

See also: BIND updates fix four serious DoS bugs

A denial-of-service (DoS) attack is a malicious attempt to disrupt the normal operation of a targeted server, service, or network by overwhelming it with a flood of Internet traffic. The primary goal of a DoS attack is to render a system unusable by denying access to legitimate users. These attacks typically exploit vulnerabilities or overload systems with excessive requests, exhausting their resources and causing downtime. Cybersecurity measures, such as firewalls, load balancing systems, and intrusion detection systems, are essential to mitigate the risks and impacts of such attacks.

Source: cybersecuritynews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS