CVE-2025-20137 - CVE House
Back to Database
Status published Medium CVE-2025-20137

A vulnerability in the access control list (ACL) programming of...

Vulnerability Description

A vulnerability in the access control list (ACL) programming of Cisco IOS Software that is running on Cisco Catalyst 1000 Switches and Cisco Catalyst 2960L Switches could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to the use of both an IPv4 ACL and a dynamic ACL of IP Source Guard on the same interface, which is an unsupported configuration. An attacker could exploit this vulnerability by attempting to send traffic through an affected device. A successful exploit could allow the attacker to bypass an ACL on the affected device. Note: Cisco documentation has been updated to reflect that this is an unsupported configuration. However, Cisco is publishing this advisory because the device will not prevent an administrator from configuring both features on the same interface. There are no plans to implement the ability to configure both features on the same interface on Cisco Catalyst 1000 or Catalyst 2960L Switches.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-20137

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

IOS
Vulnerable Versions:
15.2(5a)E, 15.2(5b)E, 15.2(5c)E, 15.2(6)E, 15.2(6)E1, 15.2(6)E0c, 15.2(6)E2, 15.2(7)E, 15.2(6)E2b, 15.2(7)E1, 15.2(7)E0a, 15.2(7)E0s, 15.2(6)E3, 15.2(7)E2, 15.2(7a)E0b, 15.2(7)E3, 15.2(7)E1a, 15.2(7b)E0b, 15.2(7)E4, 15.2(7)E3k, 15.2(8)E, 15.2(8)E1, 15.2(7)E5, 15.2(7)E6, 15.2(8)E2, 15.2(7)E7, 15.2(8)E3, 15.2(7)E8, 15.2(8)E4, 15.2(7)E9, 15.2(8)E5, 15.2(8)E6, 15.2(7)E10, 15.2(7)E11, 15.2(7)E12

Timeline

Official Publish: May 7th, 2025
Last Modified: May 7th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N

Weaknesses (CWE)