CVE-2025-20162

HIGH

Cisco IOS XE - Unauthenticated Denial of Service via DHCP Snooping Packet Handling

Title source: llm
STIX 2.1

Description

A vulnerability in the DHCP snooping security feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a full interface queue wedge, which could result in a denial of service (DoS) condition. This vulnerability is due to improper handling of DHCP request packets. An attacker could exploit this vulnerability by sending DHCP request packets to an affected device. A successful exploit could allow the attacker to cause packets to wedge in the queue, creating a DoS condition for downstream devices of the affected system and requiring that the system restart to drain the queue. Note: This vulnerability can be exploited with either unicast or broadcast DHCP packets on a VLAN that does not have DHCP snooping enabled.

Scores

CVSS v3 8.6
EPSS 0.0046
EPSS Percentile 64.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-400
Status published
Products (50)
cisco/ios_xe 16.11.1
cisco/ios_xe 16.11.1a
cisco/ios_xe 16.11.1s
cisco/ios_xe 16.11.2
cisco/ios_xe 16.12.1
cisco/ios_xe 16.12.1a
cisco/ios_xe 16.12.1c
cisco/ios_xe 16.12.1s
cisco/ios_xe 16.12.2
cisco/ios_xe 16.12.2s
... and 40 more
Published May 07, 2025
Tracked Since Feb 18, 2026