CVE-2025-20191 - CVE House
Back to Database
Status published High CVE-2025-20191

Multiple Cisco Products Denial of Service Vulnerability

Vulnerability Description

A vulnerability in the Switch Integrated Security Features (SISF) of Cisco IOS Software, Cisco IOS XE Software, Cisco NX-OS Software, and Cisco Wireless LAN Controller (WLC) AireOS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to the incorrect handling of DHCPv6 packets. An attacker could exploit this vulnerability by sending a crafted DHCPv6 packet to an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-20191

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Cisco NX-OS Software, Cisco Wireless LAN Controller (WLC)
Vulnerable Versions:
8.2(5), 7.3(5)D1(1), 8.4(2), 8.4(3), 9.2(3), 9.2(2v), 7.3(4)D1(1), 8.2(1), 9.2(1), 9.2(2t), 9.2(3y), 7.0(3)I7(6z), 9.3(2), 7.0(3)I7(3z), 7.0(3)IM7(2), 7.0(3)I7(5a), 8.1(1), 8.2(2), 8.3(2), 7.3(2)D1(3a), 9.2(4), 8.1(2), 7.3(3)D1(1), 8.2(3), 7.0(3)I7(2), 7.0(3)I7(3), 8.4(1), 7.3(0)DX(1), 7.3(2)D1(1), 9.3(1), 7.0(3)I7(6), 7.3(2)D1(2), 8.2(4), 7.0(3)I7(4), 7.0(3)I7(7), 9.3(1z), 9.2(2), 8.1(2a), 7.3(2)D1(3), 7.0(3)I7(5), 7.0(3)I7(1), 7.0(3)IA7(2), 7.0(3)IA7(1), 8.3(1), 7.3(1)D1(1), 7.3(0)D1(1), 9.3(3), 7.3(2)D1(1d), 7.0(3)I7(8), 9.3(4), 7.3(6)D1(1), 8.2(6), 9.3(5), 7.0(3)I7(9), 9.3(6), 10.1(2), 10.1(1), 8.4(4), 7.3(7)D1(1), 9.3(5w), 8.2(7), 9.3(7), 9.3(7k), 7.0(3)I7(9w), 10.2(1), 7.3(8)D1(1), 9.3(7a), 8.2(7a), 9.3(8), 8.4(4a), 8.4(5), 7.0(3)I7(10), 8.2(8), 10.2(1q), 10.2(2), 9.3(9), 10.1(2t), 7.3(9)D1(1), 10.2(3), 8.4(6), 10.2(3t), 9.3(10), 10.2(2a), 8.2(9), 10.3(1), 10.2(4), 8.4(7), 10.3(2), 8.4(6a), 9.3(11), 10.3(3), 10.2(5), 8.2(10), 9.3(12), 10.2(3v), 10.4(1), 8.4(8), 10.3(99w), 10.2(6), 10.3(3w), 10.3(99x), 10.3(3o), 8.4(9), 10.3(4), 10.3(3p), 10.3(4a), 10.4(2), 10.3(3q), 9.3(13), 8.2(11), 10.3(5), 10.2(7), 10.4(3), 10.3(3x), 10.3(4g), 10.2(8), 10.3(3r), 9.3(14), 10.3(4h), 8.10.112.0, 8.8.120.0, 8.3.143.0, 8.3.111.0, 8.2.164.0, 8.5.109.0, 8.3.132.0, 8.5.105.0, 8.2.170.0, 8.2.160.0, 8.8.100.0, 8.9.111.0, 8.7.102.0, 8.3.102.0, 8.3.133.0, 8.3.131.0, 8.5.100.0, 8.5.131.0, 8.3.122.0, 8.5.101.0, 8.3.112.0, 8.5.120.0, 8.2.141.0, 8.3.141.0, 8.3.121.0, 8.2.151.0, 8.3.130.0, 8.5.102.0, 8.2.161.0, 8.5.151.0, 8.2.100.0, 8.5.135.0, 8.3.135.0, 8.5.140.0, 8.7.106.0, 8.9.100.0, 8.8.111.0, 8.2.110.0, 8.5.110.0, 8.2.130.0, 8.5.141.105, 8.2.121.0, 8.8.125.0, 8.3.150.0, 8.2.111.0, 8.10.105.0, 8.5.108.0, 8.3.108.0, 8.2.166.0, 8.5.103.0, 8.3.140.0, 8.6.101.0, 8.4.100.0, 8.5.160.0, 8.5.161.0, 8.8.130.0, 8.10.120.0, 8.10.121.0, 8.10.113.0, 8.10.122.0, 8.10.130.0, 8.10.141.0, 8.10.142.0, 8.5.171.0, 8.10.150.0, 8.10.151.0, 8.10.162.0, 8.5.182.0, 8.10.171.0, 8.10.180.0, 8.10.181.0, 8.10.182.0, 8.10.170.0, 8.10.183.0, 8.5.182.7, 8.5.182.105, 8.5.182.106, 8.10.185.0, 8.5.182.107, 8.5.182.11, 8.5.182.108, 8.10.190.0, 8.10.195.0, 8.5.182.12

Timeline

Official Publish: May 7th, 2025
Last Modified: May 7th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.