CVE-2025-20313
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/09/2025
Last modified:
26/09/2025
Description
Multiple vulnerabilities in Cisco IOS XE Software of could allow an authenticated, local attacker with level-15 privileges or an unauthenticated attacker with physical access to the device to execute persistent code at boot time and break the chain of trust.<br />
<br />
These vulnerabilities are due path traversal and improper image integrity validation. A successful exploit could allow the attacker to execute persistent code on the underlying operating system.<br />
<br />
Because this allows the attacker to bypass a major security feature of the device, Cisco has raised the Security Impact Rating (SIR) of this advisory from Medium to High.<br />
<br />
For more information about these vulnerabilities, see the Details ["#details"] section of this advisory.<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
ERP
Impact
Base Score 3.x
6.70
Severity 3.x
MEDIUM



