CVE-2025-20221

MEDIUM

Cisco IOS XE SD-WAN - Unauthenticated Traffic Filter Bypass via Crafted Packet

Title source: llm
STIX 2.1

Description

A vulnerability in the packet filtering features of Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to bypass Layer 3 and Layer 4 traffic filters. This vulnerability is due to improper traffic filtering conditions on an affected device. An attacker could exploit this vulnerability by sending a crafted packet to the affected device. A successful exploit could allow the attacker to bypass the Layer 3 and Layer 4 traffic filters and inject a crafted packet into the network.

Scores

CVSS v3 5.3
EPSS 0.0010
EPSS Percentile 27.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-200
Status published
Products (50)
cisco/ios_xe 16.12.13
cisco/ios_xe 17.1.1
cisco/ios_xe 17.1.1s
cisco/ios_xe 17.1.1t
cisco/ios_xe 17.1.3
cisco/ios_xe 17.2.1
cisco/ios_xe 17.2.1a
cisco/ios_xe 17.2.1r
cisco/ios_xe 17.2.1v
cisco/ios_xe 17.2.2
... and 40 more
Published May 07, 2025
Tracked Since Feb 18, 2026