CVE-2025-20221
MEDIUMCisco IOS XE SD-WAN - Unauthenticated Traffic Filter Bypass via Crafted Packet
Title source: llmDescription
A vulnerability in the packet filtering features of Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to bypass Layer 3 and Layer 4 traffic filters. This vulnerability is due to improper traffic filtering conditions on an affected device. An attacker could exploit this vulnerability by sending a crafted packet to the affected device. A successful exploit could allow the attacker to bypass the Layer 3 and Layer 4 traffic filters and inject a crafted packet into the network.
References (1)
Core 1
Core References
Scores
CVSS v3
5.3
EPSS
0.0010
EPSS Percentile
27.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-200
Status
published
Products (50)
cisco/ios_xe
16.12.13
cisco/ios_xe
17.1.1
cisco/ios_xe
17.1.1s
cisco/ios_xe
17.1.1t
cisco/ios_xe
17.1.3
cisco/ios_xe
17.2.1
cisco/ios_xe
17.2.1a
cisco/ios_xe
17.2.1r
cisco/ios_xe
17.2.1v
cisco/ios_xe
17.2.2
... and 40 more
Published
May 07, 2025
Tracked Since
Feb 18, 2026