CVE-2025-20181

MEDIUMCVSS 6.8/10EPSS 0.16%

Last modified

CVE-2025-20181 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. A vulnerability in Cisco IOS Software for Cisco Catalyst 2960X, 2960XR, 2960CX, and 3560CX Series Switches could allow an authenticated, local attacker with privilege level 15 or an unauthenticated attacker with physical access to the device to execute persistent code at boot time and break the chain of trust. This vulnerability is due to missing signature verification for specific files that may be loaded during the device boot process. An attacker could exploit this vulnerability by placing a crafted file into a specific location on an affected device. EPSS estimates a 0.16% chance of exploitation in the next 30 days.

Description

A vulnerability in Cisco IOS Software for Cisco Catalyst 2960X, 2960XR, 2960CX, and 3560CX Series Switches could allow an authenticated, local attacker with privilege level 15 or an unauthenticated attacker with physical access to the device to execute persistent code at boot time and break the chain of trust. This vulnerability is due to missing signature verification for specific files that may be loaded during the device boot process. An attacker could exploit this vulnerability by placing a crafted file into a specific location on an affected device. A successful exploit could allow the attacker to execute arbitrary code at boot time. Because this allows the attacker to bypass a major security feature of the device, Cisco has raised the Security Impact Rating (SIR) of this advisory from Medium to High.

Metrics

CVSS 3.0
6.8/10

CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.16%

5.4th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
CiscoIos15.0\(1\)ex
CiscoIos15.0\(1\)ey
CiscoIos15.0\(1\)ey1
CiscoIos15.0\(1\)ey2
CiscoIos15.0\(1\)xo
CiscoIos15.0\(1\)xo1
CiscoIos15.0\(2\)ex
CiscoIos15.0\(2\)ex1
CiscoIos15.0\(2\)ex2
CiscoIos15.0\(2\)ex3
CiscoIos15.0\(2\)ex4
CiscoIos15.0\(2\)ex5
CiscoIos15.0\(2\)ex8
CiscoIos15.0\(2\)ex10
CiscoIos15.0\(2\)ex11
CiscoIos15.0\(2\)ex12
CiscoIos15.0\(2\)ex13
CiscoIos15.0\(2\)se8
CiscoIos15.0\(2\)sqd
CiscoIos15.0\(2\)sqd1
CiscoIos15.0\(2\)sqd2
CiscoIos15.0\(2\)sqd3
CiscoIos15.0\(2\)sqd4
CiscoIos15.0\(2\)sqd5
CiscoIos15.0\(2\)sqd6
CiscoIos15.0\(2\)sqd7
CiscoIos15.0\(2\)sqd8
CiscoIos15.0\(2\)xo
CiscoIos15.0\(2a\)ex5
CiscoIos15.2\(2\)e
CiscoIos15.2\(2\)e1
CiscoIos15.2\(2\)e2
CiscoIos15.2\(2\)e3
CiscoIos15.2\(2\)e4
CiscoIos15.2\(2\)e5
CiscoIos15.2\(2\)e5a
CiscoIos15.2\(2\)e5b
CiscoIos15.2\(2\)e6
CiscoIos15.2\(2\)e7
CiscoIos15.2\(2\)e8
CiscoIos15.2\(2\)e9
CiscoIos15.2\(2\)e10
CiscoIos15.2\(2a\)e1
CiscoIos15.2\(2a\)e2
CiscoIos15.2\(3\)e
CiscoIos15.2\(3\)e1
CiscoIos15.2\(3\)e2
CiscoIos15.2\(3\)e3
CiscoIos15.2\(3\)e4
CiscoIos15.2\(3a\)e

Showing 50 of 106 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2025-20181?
A vulnerability in Cisco IOS Software for Cisco Catalyst 2960X, 2960XR, 2960CX, and 3560CX Series Switches could allow an authenticated, local attacker with privilege level 15 or an unauthenticated attacker with physical access to the device to execute persistent code at boot time and break the chain of trust. This vulnerability is due to missing signature verification for specific files that may be loaded during the device boot process. An attacker could exploit this vulnerability by placing a crafted file into a specific location on an affected device. A successful exploit could allow the attacker to execute arbitrary code at boot time. Because this allows the attacker to bypass a major security feature of the device, Cisco has raised the Security Impact Rating (SIR) of this advisory from Medium to High.
How severe is CVE-2025-20181?
CVE-2025-20181 has a CVSS score of 6.8/10 (MEDIUM severity). The EPSS model estimates a 0.16% probability of exploitation in the next 30 days.
How do I fix CVE-2025-20181?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2025-20181?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST