CVE-2025-20313

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/09/2025
Last modified:
26/09/2025

Description

Multiple vulnerabilities in Cisco IOS XE Software of could allow an authenticated, local attacker with level-15 privileges or an unauthenticated attacker with physical access to the device to execute persistent code at boot time and break the chain of trust.<br /> <br /> These vulnerabilities are due path traversal and improper image integrity validation. A successful exploit could allow the attacker to execute persistent code on the underlying operating system.<br /> <br /> Because this allows the attacker to bypass a major security feature of the device, Cisco has raised the Security Impact Rating (SIR) of this advisory from Medium to High.<br /> <br /> For more information about these vulnerabilities, see the Details ["#details"] section of this advisory.<br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> ERP