CVE-2025-20162
Severity CVSS v4.0:
Pending analysis
Type:
CWE-400
Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
07/05/2025
Last modified:
11/07/2025
Description
A vulnerability in the DHCP snooping security feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a full interface queue wedge, which could result in a denial of service (DoS) condition.<br />
<br />
This vulnerability is due to improper handling of DHCP request packets. An attacker could exploit this vulnerability by sending DHCP request packets to an affected device. A successful exploit could allow the attacker to cause packets to wedge in the queue, creating a DoS condition for downstream devices of the affected system and requiring that the system restart to drain the queue.<br />
<br />
Note: This vulnerability can be exploited with either unicast or broadcast DHCP packets on a VLAN that does not have DHCP snooping enabled.
Impact
Base Score 3.x
8.60
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:cisco:ios_xe:16.11.1:*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:ios_xe:16.11.1a:*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:ios_xe:16.11.1s:*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:ios_xe:16.11.2:*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:ios_xe:16.12.1:*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:ios_xe:16.12.1a:*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:ios_xe:16.12.1c:*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:ios_xe:16.12.1s:*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:ios_xe:16.12.2:*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:ios_xe:16.12.2s:*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:ios_xe:16.12.3:*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:ios_xe:16.12.3s:*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:ios_xe:16.12.4:*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:ios_xe:16.12.5:*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:ios_xe:16.12.6:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



