Buffer Access with Incorrect Length Value in Cisco Systems, Inc products - CVE-2025-20191

 

Buffer Access with Incorrect Length Value in Cisco Systems, Inc products - CVE-2025-20191

Published: May 9, 2025


Vulnerability identifier: #VU108841
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-20191
CWE-ID: CWE-805
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to the incorrect handling of DHCPv6 packets in the Switch Integrated Security Features (SISF). A remote attacker on the local network can send a specially crafted DHCPv6 packet and cause a denial of service condition on the target system.


Affected software

Cisco IOS
Cisco NX-OS
Cisco IOS XE
Cisco Wireless LAN Controller (WLC) AireOS Software

How to mitigate CVE-2025-20191

Install updates from vendor's website.

Cisco NX-OS - addressed in versions 8.4(10), 8.4(11), 9.3(15), 10.2(9), 10.3(6), 10.3(7), 10.4(4), 10.4(5), 10.5(1), 10.5(2), 10.5(3)
Cisco Wireless LAN Controller (WLC) AireOS Software - addressed in versions Gibraltar-16.12.1s, 8.10.196.0, 8.10.196.4, 16.12.1, 16.12.1c, 16.12.1s, 16.12.1t, 16.12.1v, 16.12.1w, 16.12.1x, 16.12.1y, 16.12.1z, 16.12.1z1, 16.12.1z2, 16.12.1a, 16.12.2, 16.12.2s, 16.12.2t, 16.12.2a, 16.12.3, 16.12.3s, 16.12.3a, 16.12.4, 16.12.4a, 16.12.5, 16.12.5a, 16.12.5b, 16.12.6, 16.12.6a, 16.12.7, 17.1.1, 17.1.1s, 17.1.1t, 17.1.1a, 17.1.2, 17.1.3, 17.2.1, 17.2.1v, 17.2.1LA, 17.2.1a, 17.2.1r, 17.2.2, 17.2.3, 17.3.1, 17.3.1w, 17.3.1x, 17.3.1z, 17.3.1a, 17.3.2, 17.3.2a, 17.3.3, 17.3.3a, 17.3.4, 17.3.4c, 17.3.4a, 17.3.4b, 17.4.1, 17.4.1c, 17.4.1a, 17.4.1b, 17.4.2, 17.4.2a, 17.5.1, 17.5.1a, 17.6.1, 17.6.1w, 17.6.1x, 17.6.1a, 17.6.2, 17.7.1, 17.7.1a
Cisco IOS XE - addressed in versions 16.12.2, 16.12.2s, 16.12.2t, 16.12.2a, 16.12.3, 16.12.3s, 16.12.3a, 16.12.4, 16.12.4a, 16.12.5, 16.12.5a, 16.12.5 b, 16.12.6, 16.12.6a, 16.12.7, 16.12.8, 16.12.9, 16.12.10, 16.12.10a, 16.12.11, 16.12.12, 16.12.13, 17.1.1, 17.1.1s, 17.1.1t, 17.1.1a, 17.1.2, 17.1.3, 17.2.1, 17.2.1v, 17.2.1LA, 17.2.1a, 17.2.1r, 17.2.2, 17.2.3, 17.3.1, 17.3.1w, 17.3.1x, 17.3.1z, 17.3.1a, 17.3.2, 17.3.2a, 17.3.3, 17.3.3a, 17.3.4, 17.3.4c, 17.3.4a, 17.3.4 b, 17.3.5, 17.3.5a, 17.3.5b, 17.3.6, 17.3.7, 17.3.8, 17.3.8a, 17.4.1, 17.4.1c, 17.4.1a, 17.4.1b, 17.4.2, 17.4.2a, 17.5.1, 17.5.1c, 17.05.01c, 17.5.1a, 17.5.1b, 17.6.1, 17.6.1w, 17.6.1x, 17.6.1y, 17.6.1z, 17.6.1z1, 17.6.1a, 17.6.2, 17.6.3, 17.6.3a, 17.6.4, 17.6.5, 17.6.5a, 17.6.6, 17.6.6a, 17.6.7, 17.6.8, 17.7.1, 17.7.1a, 17.7.1b, 17.7.2, 17.8.1, 17.8.1a, 17.9.1, 17.9.1w, 17.9.1x, 17.9.1x1, 17.9.1y, 17.9.1y1, 17.9.1a, 17.9.2, 17.9.2a, 17.9.3, 17.9.3a, 17.9.4, 17.9.4a, 17.9.5, 17.9.5c, 17.9.5d, 17.9.5e, 17.9.5f, 17.9.5a, 17.9.5b, 17.9.6, 17.9.6a, 17.9.6b, 17.9.7, 17.9.7a, 17.10.1, 17.10.1a, 17.10.1b, 17.11.1, 17.11.1a, 17.12.1, 17.12.1w, 17.12.1x, 17.12.1y, 17.12.1z1, 17.12.1z2, 17.12.1z3, 17.12.1z4, 17.12.1a, 17.12.2, 17.12.3, 17.12.3a, 17.12.4, 17.12.4a, 17.12.4b, 17.12.5, 17.12.5a, 17.13.1a, 17.14.1, 17.14.1a, 17.15.1, 17.15.1w, 17.15.1x, 17.15.1y, 17.15.1a, 17.15.1b, 17.15.2, 17.15.2c, 17.15.2a, 17.15.2b, 17.15.3, 17.15.3a, 17.16.1, 17.16.1a, 17.17.1

External References

Related Security Bulletins