#VU116080 Improper authentication in Cisco IOS XE - CVE-2025-20160
Published: September 24, 2025
Cisco IOS XE
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in the implementation of the TACACS+ protocol where the system does not properly check whether the required TACACS+ shared secret was configured. A remote machine-in-the-middle attacker can read unencrypted TACACS+ messages or impersonate the TACACS+ server and falsely accept arbitrary authentication requests, leading to information disclosure.