Close Menu
  • Home
  • Opinion
  • Region
    • Africa
    • Asia
    • Europe
    • Middle East
    • North America
    • Oceania
    • South America
  • AI & Machine Learning
  • Robotics & Automation
  • Space & Deep Tech
  • Web3 & Digital Economies
  • Climate & Sustainability Tech
  • Biotech & Future Health
  • Mobility & Smart Cities
  • Global Tech Pulse
  • Cybersecurity & Digital Rights
  • Future of Work & Education
  • Trend Radar & Startup Watch
  • Creator Economy & Culture
What's Hot

15pc cap on EU pharma exports to US nonetheless applies, says Tánaiste

September 26, 2025

Straightforward Steps to Seize and Accumulate Logs from Galaxy Watch

September 26, 2025

Sakana AI Launched ShinkaEvolve: An Open-Supply Framework that Evolves Packages for Scientific Discovery with Unprecedented Pattern-Effectivity

September 26, 2025
Facebook X (Twitter) Instagram LinkedIn RSS
NextTech NewsNextTech News
Facebook X (Twitter) Instagram LinkedIn RSS
  • Home
  • Africa
  • Asia
  • Europe
  • Middle East
  • North America
  • Oceania
  • South America
  • Opinion
Trending
  • 15pc cap on EU pharma exports to US nonetheless applies, says Tánaiste
  • Straightforward Steps to Seize and Accumulate Logs from Galaxy Watch
  • Sakana AI Launched ShinkaEvolve: An Open-Supply Framework that Evolves Packages for Scientific Discovery with Unprecedented Pattern-Effectivity
  • The high-stakes push to construct Nigeria’s first open-source LLM
  • Roadmap goals to set EU transport on path to net-zero
  • Traditional Casio F-91W Will get a Fashionable Makeover with Ollee Watch, Full with Video games
  • Korea Seeks to Lengthen Fund of Funds Past 2035, Strengthening Entry Pathways for International Innovators – KoreaTechDesk
  • NIGCOMSAT, Kenyan House Company open talks on shared satellite tv for pc
Friday, September 26
NextTech NewsNextTech News
Home - Cybersecurity & Digital Rights - Cisco Warns of Actively Exploited SNMP Vulnerability Permitting RCE or DoS in IOS Software program
Cybersecurity & Digital Rights

Cisco Warns of Actively Exploited SNMP Vulnerability Permitting RCE or DoS in IOS Software program

NextTechBy NextTechSeptember 25, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Follow Us
Google News Flipboard
Cisco Warns of Actively Exploited SNMP Vulnerability Permitting RCE or DoS in IOS Software program
Share
Facebook Twitter LinkedIn Pinterest Email


Sep 25, 2025Ravie LakshmananVulnerability / Community Safety

Cisco has warned of a high-severity safety flaw in IOS Software program and IOS XE Software program that would permit a distant attacker to execute arbitrary code or set off a denial-of-service (DoS) situation beneath particular circumstances.

The corporate mentioned the vulnerability, CVE-2025-20352 (CVSS rating: 7.7), has been exploited within the wild, including it turned conscious of it “after native Administrator credentials had been compromised.”

The problem, per the networking tools main, is rooted within the Easy Community Administration Protocol (SNMP) subsystem, arising on account of a stack overflow situation.

An authenticated, distant attacker might exploit the flaw by sending a crafted SNMP packet to an affected gadget over IPv4 or IPv6 networks, leading to DoS if they’ve low privileges or arbitrary code execution as root if they’ve excessive privileges and finally take management of the vulnerable system.

DFIR Retainer Services

Nevertheless, Cisco famous that for this to occur, the next circumstances have to be met –

  • To trigger the DoS, the attacker will need to have the SNMPv2c or earlier read-only neighborhood string or legitimate SNMPv3 consumer credentials
  • To execute code as the basis consumer, the attacker will need to have the SNMPv1 or v2c read-only neighborhood string or legitimate SNMPv3 consumer credentials and administrative or privilege 15 credentials on the affected gadget

The corporate mentioned the problem impacts all variations of SNMP, in addition to Meraki MS390 and Cisco Catalyst 9300 Collection Switches which might be operating Meraki CS 17 and earlier. It has been mounted in Cisco IOS XE Software program Launch 17.15.4a. Cisco IOS XR Software program and NX-OS Software program aren’t impacted.

“This vulnerability impacts all variations of SNMP. All gadgets which have SNMP enabled and haven’t explicitly excluded the affected object ID (OID) must be thought-about weak,” Cisco mentioned.

Whereas there aren’t any workarounds that resolve CVE-2025-20352, one mitigation proposed by Cisco entails permitting solely trusted customers to have SNMP entry on an affected system, and monitoring the methods by operating the “present snmp host” command.

“Directors can disable the affected OIDs on a tool,” it added. “Not all software program will help the OID that’s listed within the mitigation. If the OID is just not legitimate for particular software program, then it’s not affected by this vulnerability. Excluding these OIDs might have an effect on gadget administration via SNMP, reminiscent of discovery and {hardware} stock.”

Elevate your perspective with NextTech Information, the place innovation meets perception.
Uncover the most recent breakthroughs, get unique updates, and join with a worldwide community of future-focused thinkers.
Unlock tomorrow’s traits at the moment: learn extra, subscribe to our e-newsletter, and change into a part of the NextTech neighborhood at NextTech-news.com

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
NextTech
  • Website

Related Posts

Cisco ASA Firewall Zero-Day Exploits Deploy RayInitiator and LINE VIPER Malware

September 26, 2025

The €600,000 gold heist, powered by ransomware • Graham Cluley

September 25, 2025

Chinese language Hackers RedNovember Goal International Governments Utilizing Pantegana and Cobalt Strike

September 24, 2025
Add A Comment
Leave A Reply Cancel Reply

Economy News

15pc cap on EU pharma exports to US nonetheless applies, says Tánaiste

By NextTechSeptember 26, 2025

As Donald Trump introduced 100pc tariffs on patented pharma merchandise coming into the US, Eire’s…

Straightforward Steps to Seize and Accumulate Logs from Galaxy Watch

September 26, 2025

Sakana AI Launched ShinkaEvolve: An Open-Supply Framework that Evolves Packages for Scientific Discovery with Unprecedented Pattern-Effectivity

September 26, 2025
Top Trending

15pc cap on EU pharma exports to US nonetheless applies, says Tánaiste

By NextTechSeptember 26, 2025

As Donald Trump introduced 100pc tariffs on patented pharma merchandise coming into…

Straightforward Steps to Seize and Accumulate Logs from Galaxy Watch

By NextTechSeptember 26, 2025

The dumpstate go surfing Galaxy Watch operating Put on OS powered by…

Sakana AI Launched ShinkaEvolve: An Open-Supply Framework that Evolves Packages for Scientific Discovery with Unprecedented Pattern-Effectivity

By NextTechSeptember 26, 2025

Sakana AI has launched ShinkaEvolve, an open-sourced framework that makes use of…

Subscribe to News

Get the latest sports news from NewsSite about world, sports and politics.

NEXTTECH-LOGO
Facebook X (Twitter) Instagram YouTube

AI & Machine Learning

Robotics & Automation

Space & Deep Tech

Web3 & Digital Economies

Climate & Sustainability Tech

Biotech & Future Health

Mobility & Smart Cities

Global Tech Pulse

Cybersecurity & Digital Rights

Future of Work & Education

Creator Economy & Culture

Trend Radar & Startup Watch

News By Region

Africa

Asia

Europe

Middle East

North America

Oceania

South America

2025 © NextTech-News. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms Of Service
  • Advertise With Us
  • Write For Us
  • Submit Article & Press Release

Type above and press Enter to search. Press Esc to cancel.

Subscribe For Latest Updates

Sign up to best of Tech news, informed analysis and opinions on what matters to you.

Invalid email address
 We respect your inbox and never send spam. You can unsubscribe from our newsletter at any time.     
Thanks for subscribing!