Description
A vulnerability in the packet filtering features of Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to bypass Layer 3 and Layer 4 traffic filters.
This vulnerability is due to improper traffic filtering conditions on an affected device. An attacker could exploit this vulnerability by sending a crafted packet to the affected device. A successful exploit could allow the attacker to bypass the Layer 3 and Layer 4 traffic filters and inject a crafted packet into the network.
Reserved 2024-10-10 | Published 2025-05-07 | Updated 2025-05-07 | Assigner
ciscoMEDIUM: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Problem types
Exposure of Sensitive Information to an Unauthorized Actor
Product status
16.12.13
affected
17.1.1
affected
17.1.1s
affected
17.1.1t
affected
17.1.3
affected
17.2.1
affected
17.2.1r
affected
17.2.1a
affected
17.2.1v
affected
17.2.2
affected
17.2.3
affected
17.3.1
affected
17.3.2
affected
17.3.3
affected
17.3.1a
affected
17.3.2a
affected
17.3.4
affected
17.3.5
affected
17.3.4a
affected
17.3.6
affected
17.3.7
affected
17.3.8
affected
17.3.8a
affected
17.4.1
affected
17.4.2
affected
17.4.1a
affected
17.4.1b
affected
17.5.1
affected
17.5.1a
affected
17.6.1
affected
17.6.2
affected
17.6.1a
affected
17.6.3
affected
17.6.1y
affected
17.6.3a
affected
17.6.4
affected
17.6.5
affected
17.6.6
affected
17.6.6a
affected
17.6.5a
affected
17.6.7
affected
17.6.8
affected
17.6.8a
affected
17.7.1
affected
17.7.1a
affected
17.7.2
affected
17.10.1
affected
17.10.1a
affected
17.10.1b
affected
17.8.1
affected
17.8.1a
affected
17.9.1
affected
17.9.2
affected
17.9.1a
affected
17.9.3
affected
17.9.2a
affected
17.9.3a
affected
17.9.4
affected
17.9.5
affected
17.9.4a
affected
17.9.5a
affected
17.9.5b
affected
17.9.6
affected
17.9.6a
affected
17.9.5e
affected
17.9.5f
affected
17.11.1
affected
17.11.1a
affected
17.12.1
affected
17.12.1a
affected
17.12.2
affected
17.12.3
affected
17.12.4
affected
17.12.3a
affected
17.12.1z2
affected
17.12.4a
affected
17.12.4b
affected
17.13.1
affected
17.13.1a
affected
17.14.1
affected
17.14.1a
affected
17.15.1
affected
17.15.1a
affected
17.15.2
affected
17.15.1x
affected
17.15.2c
affected
17.15.2b
affected
17.16.1
affected
17.16.1a
affected
References
sec.cloudapps.cisco.com/...ory/cisco-sa-snmp-bypass-HHUVujdn (cisco-sa-snmp-bypass-HHUVujdn)
cve.org (CVE-2025-20221)
nvd.nist.gov (CVE-2025-20221)
Download JSON