CVE-2025-20181 (GCVE-0-2025-20181)
Vulnerability from cvelistv5
Published
2025-05-07 17:35
Modified
2025-05-07 19:45
CWE
  • CWE-347 - Improper Verification of Cryptographic Signature
Summary
A vulnerability in Cisco IOS Software for Cisco Catalyst 2960X, 2960XR, 2960CX, and 3560CX Series Switches could allow an authenticated, local attacker with privilege level 15 or an unauthenticated attacker with physical access to the device to execute persistent code at boot time and break the chain of trust. This vulnerability is due to missing signature verification for specific files that may be loaded during the device boot process. An attacker could exploit this vulnerability by placing a crafted file into a specific location on an affected device. A successful exploit could allow the attacker to execute arbitrary code at boot time. Because this allows the attacker to bypass a major security feature of the device, Cisco has raised the Security Impact Rating (SIR) of this advisory from Medium to High.
Impacted products
Vendor Product Version
Cisco IOS Version: 15.0(1)XO1
Version: 15.0(1)XO
Version: 15.0(2)XO
Version: 15.0(1)EY
Version: 15.0(1)EY1
Version: 15.0(1)EY2
Version: 15.0(2)SE8
Version: 15.0(1)EX
Version: 15.0(2)EX
Version: 15.0(2)EX1
Version: 15.0(2)EX2
Version: 15.0(2)EX3
Version: 15.0(2)EX4
Version: 15.0(2)EX5
Version: 15.0(2)EX8
Version: 15.0(2a)EX5
Version: 15.0(2)EX10
Version: 15.0(2)EX11
Version: 15.0(2)EX13
Version: 15.0(2)EX12
Version: 15.2(2)E
Version: 15.2(3)E
Version: 15.2(2)E1
Version: 15.2(4)E
Version: 15.2(3)E1
Version: 15.2(2)E2
Version: 15.2(2a)E1
Version: 15.2(2)E3
Version: 15.2(2a)E2
Version: 15.2(3)E2
Version: 15.2(3a)E
Version: 15.2(3)E3
Version: 15.2(4)E1
Version: 15.2(2)E4
Version: 15.2(2)E5
Version: 15.2(4)E2
Version: 15.2(3)E4
Version: 15.2(5)E
Version: 15.2(4)E3
Version: 15.2(2)E6
Version: 15.2(5)E1
Version: 15.2(5b)E
Version: 15.2(2)E5a
Version: 15.2(2)E5b
Version: 15.2(4)E4
Version: 15.2(2)E7
Version: 15.2(5)E2
Version: 15.2(6)E
Version: 15.2(4)E5
Version: 15.2(2)E8
Version: 15.2(6)E0a
Version: 15.2(6)E1
Version: 15.2(6)E0c
Version: 15.2(4)E6
Version: 15.2(6)E2
Version: 15.2(2)E9
Version: 15.2(4)E7
Version: 15.2(7)E
Version: 15.2(2)E10
Version: 15.2(4)E8
Version: 15.2(6)E2a
Version: 15.2(6)E2b
Version: 15.2(7)E1
Version: 15.2(7)E0a
Version: 15.2(7)E0b
Version: 15.2(7)E0s
Version: 15.2(6)E3
Version: 15.2(4)E9
Version: 15.2(7)E2
Version: 15.2(7a)E0b
Version: 15.2(4)E10
Version: 15.2(7)E3
Version: 15.2(7)E1a
Version: 15.2(7b)E0b
Version: 15.2(7)E2a
Version: 15.2(4)E10a
Version: 15.2(7)E4
Version: 15.2(7)E3k
Version: 15.2(8)E
Version: 15.2(8)E1
Version: 15.2(7)E5
Version: 15.2(7)E6
Version: 15.2(8)E2
Version: 15.2(4)E10d
Version: 15.2(7)E7
Version: 15.2(8)E3
Version: 15.2(7)E8
Version: 15.2(8)E4
Version: 15.2(7)E9
Version: 15.2(8)E5
Version: 15.2(8)E6
Version: 15.2(7)E10
Version: 15.2(6)EB
Version: 15.2(4)EA7
Version: 15.2(4)EA8
Version: 15.2(4)EA9
Version: 15.2(4)EA9a
Version: 15.0(2)SQD
Version: 15.0(2)SQD1
Version: 15.0(2)SQD2
Version: 15.0(2)SQD3
Version: 15.0(2)SQD4
Version: 15.0(2)SQD5
Version: 15.0(2)SQD6
Version: 15.0(2)SQD7
Version: 15.0(2)SQD8
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2025-20181",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-05-07T18:56:17.739877Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-05-07T19:45:02.742Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "IOS",
          "vendor": "Cisco",
          "versions": [
            {
              "status": "affected",
              "version": "15.0(1)XO1"
            },
            {
              "status": "affected",
              "version": "15.0(1)XO"
            },
            {
              "status": "affected",
              "version": "15.0(2)XO"
            },
            {
              "status": "affected",
              "version": "15.0(1)EY"
            },
            {
              "status": "affected",
              "version": "15.0(1)EY1"
            },
            {
              "status": "affected",
              "version": "15.0(1)EY2"
            },
            {
              "status": "affected",
              "version": "15.0(2)SE8"
            },
            {
              "status": "affected",
              "version": "15.0(1)EX"
            },
            {
              "status": "affected",
              "version": "15.0(2)EX"
            },
            {
              "status": "affected",
              "version": "15.0(2)EX1"
            },
            {
              "status": "affected",
              "version": "15.0(2)EX2"
            },
            {
              "status": "affected",
              "version": "15.0(2)EX3"
            },
            {
              "status": "affected",
              "version": "15.0(2)EX4"
            },
            {
              "status": "affected",
              "version": "15.0(2)EX5"
            },
            {
              "status": "affected",
              "version": "15.0(2)EX8"
            },
            {
              "status": "affected",
              "version": "15.0(2a)EX5"
            },
            {
              "status": "affected",
              "version": "15.0(2)EX10"
            },
            {
              "status": "affected",
              "version": "15.0(2)EX11"
            },
            {
              "status": "affected",
              "version": "15.0(2)EX13"
            },
            {
              "status": "affected",
              "version": "15.0(2)EX12"
            },
            {
              "status": "affected",
              "version": "15.2(2)E"
            },
            {
              "status": "affected",
              "version": "15.2(3)E"
            },
            {
              "status": "affected",
              "version": "15.2(2)E1"
            },
            {
              "status": "affected",
              "version": "15.2(4)E"
            },
            {
              "status": "affected",
              "version": "15.2(3)E1"
            },
            {
              "status": "affected",
              "version": "15.2(2)E2"
            },
            {
              "status": "affected",
              "version": "15.2(2a)E1"
            },
            {
              "status": "affected",
              "version": "15.2(2)E3"
            },
            {
              "status": "affected",
              "version": "15.2(2a)E2"
            },
            {
              "status": "affected",
              "version": "15.2(3)E2"
            },
            {
              "status": "affected",
              "version": "15.2(3a)E"
            },
            {
              "status": "affected",
              "version": "15.2(3)E3"
            },
            {
              "status": "affected",
              "version": "15.2(4)E1"
            },
            {
              "status": "affected",
              "version": "15.2(2)E4"
            },
            {
              "status": "affected",
              "version": "15.2(2)E5"
            },
            {
              "status": "affected",
              "version": "15.2(4)E2"
            },
            {
              "status": "affected",
              "version": "15.2(3)E4"
            },
            {
              "status": "affected",
              "version": "15.2(5)E"
            },
            {
              "status": "affected",
              "version": "15.2(4)E3"
            },
            {
              "status": "affected",
              "version": "15.2(2)E6"
            },
            {
              "status": "affected",
              "version": "15.2(5)E1"
            },
            {
              "status": "affected",
              "version": "15.2(5b)E"
            },
            {
              "status": "affected",
              "version": "15.2(2)E5a"
            },
            {
              "status": "affected",
              "version": "15.2(2)E5b"
            },
            {
              "status": "affected",
              "version": "15.2(4)E4"
            },
            {
              "status": "affected",
              "version": "15.2(2)E7"
            },
            {
              "status": "affected",
              "version": "15.2(5)E2"
            },
            {
              "status": "affected",
              "version": "15.2(6)E"
            },
            {
              "status": "affected",
              "version": "15.2(4)E5"
            },
            {
              "status": "affected",
              "version": "15.2(2)E8"
            },
            {
              "status": "affected",
              "version": "15.2(6)E0a"
            },
            {
              "status": "affected",
              "version": "15.2(6)E1"
            },
            {
              "status": "affected",
              "version": "15.2(6)E0c"
            },
            {
              "status": "affected",
              "version": "15.2(4)E6"
            },
            {
              "status": "affected",
              "version": "15.2(6)E2"
            },
            {
              "status": "affected",
              "version": "15.2(2)E9"
            },
            {
              "status": "affected",
              "version": "15.2(4)E7"
            },
            {
              "status": "affected",
              "version": "15.2(7)E"
            },
            {
              "status": "affected",
              "version": "15.2(2)E10"
            },
            {
              "status": "affected",
              "version": "15.2(4)E8"
            },
            {
              "status": "affected",
              "version": "15.2(6)E2a"
            },
            {
              "status": "affected",
              "version": "15.2(6)E2b"
            },
            {
              "status": "affected",
              "version": "15.2(7)E1"
            },
            {
              "status": "affected",
              "version": "15.2(7)E0a"
            },
            {
              "status": "affected",
              "version": "15.2(7)E0b"
            },
            {
              "status": "affected",
              "version": "15.2(7)E0s"
            },
            {
              "status": "affected",
              "version": "15.2(6)E3"
            },
            {
              "status": "affected",
              "version": "15.2(4)E9"
            },
            {
              "status": "affected",
              "version": "15.2(7)E2"
            },
            {
              "status": "affected",
              "version": "15.2(7a)E0b"
            },
            {
              "status": "affected",
              "version": "15.2(4)E10"
            },
            {
              "status": "affected",
              "version": "15.2(7)E3"
            },
            {
              "status": "affected",
              "version": "15.2(7)E1a"
            },
            {
              "status": "affected",
              "version": "15.2(7b)E0b"
            },
            {
              "status": "affected",
              "version": "15.2(7)E2a"
            },
            {
              "status": "affected",
              "version": "15.2(4)E10a"
            },
            {
              "status": "affected",
              "version": "15.2(7)E4"
            },
            {
              "status": "affected",
              "version": "15.2(7)E3k"
            },
            {
              "status": "affected",
              "version": "15.2(8)E"
            },
            {
              "status": "affected",
              "version": "15.2(8)E1"
            },
            {
              "status": "affected",
              "version": "15.2(7)E5"
            },
            {
              "status": "affected",
              "version": "15.2(7)E6"
            },
            {
              "status": "affected",
              "version": "15.2(8)E2"
            },
            {
              "status": "affected",
              "version": "15.2(4)E10d"
            },
            {
              "status": "affected",
              "version": "15.2(7)E7"
            },
            {
              "status": "affected",
              "version": "15.2(8)E3"
            },
            {
              "status": "affected",
              "version": "15.2(7)E8"
            },
            {
              "status": "affected",
              "version": "15.2(8)E4"
            },
            {
              "status": "affected",
              "version": "15.2(7)E9"
            },
            {
              "status": "affected",
              "version": "15.2(8)E5"
            },
            {
              "status": "affected",
              "version": "15.2(8)E6"
            },
            {
              "status": "affected",
              "version": "15.2(7)E10"
            },
            {
              "status": "affected",
              "version": "15.2(6)EB"
            },
            {
              "status": "affected",
              "version": "15.2(4)EA7"
            },
            {
              "status": "affected",
              "version": "15.2(4)EA8"
            },
            {
              "status": "affected",
              "version": "15.2(4)EA9"
            },
            {
              "status": "affected",
              "version": "15.2(4)EA9a"
            },
            {
              "status": "affected",
              "version": "15.0(2)SQD"
            },
            {
              "status": "affected",
              "version": "15.0(2)SQD1"
            },
            {
              "status": "affected",
              "version": "15.0(2)SQD2"
            },
            {
              "status": "affected",
              "version": "15.0(2)SQD3"
            },
            {
              "status": "affected",
              "version": "15.0(2)SQD4"
            },
            {
              "status": "affected",
              "version": "15.0(2)SQD5"
            },
            {
              "status": "affected",
              "version": "15.0(2)SQD6"
            },
            {
              "status": "affected",
              "version": "15.0(2)SQD7"
            },
            {
              "status": "affected",
              "version": "15.0(2)SQD8"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "A vulnerability in Cisco IOS Software for Cisco Catalyst 2960X, 2960XR, 2960CX, and 3560CX Series Switches could allow an authenticated, local attacker with privilege level 15 or an unauthenticated attacker with physical access to the device to execute persistent code at boot time and break the chain of trust.\r\n\r This vulnerability is due to missing signature verification for specific files that may be loaded during the device boot process. An attacker could exploit this vulnerability by placing a crafted file into a specific location on an affected device. A successful exploit could allow the attacker to execute arbitrary code at boot time.\r\n\r Because this allows the attacker to bypass a major security feature of the device, Cisco has raised the Security Impact Rating (SIR) of this advisory from Medium to High."
        }
      ],
      "exploits": [
        {
          "lang": "en",
          "value": "The Cisco Product Security Incident Response Team (PSIRT) is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory."
        }
      ],
      "metrics": [
        {
          "cvssV3_0": {
            "attackComplexity": "LOW",
            "attackVector": "PHYSICAL",
            "availabilityImpact": "HIGH",
            "baseScore": 6.8,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.0"
          },
          "format": "cvssV3_0"
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-347",
              "description": "Improper Verification of Cryptographic Signature",
              "lang": "en",
              "type": "cwe"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2025-05-07T17:35:31.850Z",
        "orgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
        "shortName": "cisco"
      },
      "references": [
        {
          "name": "cisco-sa-c2960-3560-sboot-ZtqADrHq",
          "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-c2960-3560-sboot-ZtqADrHq"
        }
      ],
      "source": {
        "advisory": "cisco-sa-c2960-3560-sboot-ZtqADrHq",
        "defects": [
          "CSCvd75918"
        ],
        "discovery": "INTERNAL"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
    "assignerShortName": "cisco",
    "cveId": "CVE-2025-20181",
    "datePublished": "2025-05-07T17:35:31.850Z",
    "dateReserved": "2024-10-10T19:15:13.225Z",
    "dateUpdated": "2025-05-07T19:45:02.742Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2025-20181\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"total\"}], \"version\": \"2.0.3\", \"timestamp\": \"2025-05-07T18:56:17.739877Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2025-05-07T18:56:19.192Z\"}}], \"cna\": {\"source\": {\"defects\": [\"CSCvd75918\"], \"advisory\": \"cisco-sa-c2960-3560-sboot-ZtqADrHq\", \"discovery\": \"INTERNAL\"}, \"metrics\": [{\"format\": \"cvssV3_0\", \"cvssV3_0\": {\"scope\": \"UNCHANGED\", \"version\": \"3.0\", \"baseScore\": 6.8, \"attackVector\": \"PHYSICAL\", \"baseSeverity\": \"MEDIUM\", \"vectorString\": \"CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\", \"integrityImpact\": \"HIGH\", \"userInteraction\": \"NONE\", \"attackComplexity\": \"LOW\", \"availabilityImpact\": \"HIGH\", \"privilegesRequired\": \"NONE\", \"confidentialityImpact\": \"HIGH\"}}], \"affected\": [{\"vendor\": \"Cisco\", \"product\": \"IOS\", \"versions\": [{\"status\": \"affected\", \"version\": \"15.0(1)XO1\"}, {\"status\": \"affected\", \"version\": \"15.0(1)XO\"}, {\"status\": \"affected\", \"version\": \"15.0(2)XO\"}, {\"status\": \"affected\", \"version\": \"15.0(1)EY\"}, {\"status\": \"affected\", \"version\": \"15.0(1)EY1\"}, {\"status\": \"affected\", \"version\": \"15.0(1)EY2\"}, {\"status\": \"affected\", \"version\": \"15.0(2)SE8\"}, {\"status\": \"affected\", \"version\": \"15.0(1)EX\"}, {\"status\": \"affected\", \"version\": \"15.0(2)EX\"}, {\"status\": \"affected\", \"version\": \"15.0(2)EX1\"}, {\"status\": \"affected\", \"version\": \"15.0(2)EX2\"}, {\"status\": \"affected\", \"version\": \"15.0(2)EX3\"}, {\"status\": \"affected\", \"version\": \"15.0(2)EX4\"}, {\"status\": \"affected\", \"version\": \"15.0(2)EX5\"}, {\"status\": \"affected\", \"version\": \"15.0(2)EX8\"}, {\"status\": \"affected\", \"version\": \"15.0(2a)EX5\"}, {\"status\": \"affected\", \"version\": \"15.0(2)EX10\"}, {\"status\": \"affected\", \"version\": \"15.0(2)EX11\"}, {\"status\": \"affected\", \"version\": \"15.0(2)EX13\"}, {\"status\": \"affected\", \"version\": \"15.0(2)EX12\"}, {\"status\": \"affected\", \"version\": \"15.2(2)E\"}, {\"status\": \"affected\", \"version\": \"15.2(3)E\"}, {\"status\": \"affected\", \"version\": \"15.2(2)E1\"}, {\"status\": \"affected\", \"version\": \"15.2(4)E\"}, {\"status\": \"affected\", \"version\": \"15.2(3)E1\"}, {\"status\": \"affected\", \"version\": \"15.2(2)E2\"}, {\"status\": \"affected\", \"version\": \"15.2(2a)E1\"}, {\"status\": \"affected\", \"version\": \"15.2(2)E3\"}, {\"status\": \"affected\", \"version\": \"15.2(2a)E2\"}, {\"status\": \"affected\", \"version\": \"15.2(3)E2\"}, {\"status\": \"affected\", \"version\": \"15.2(3a)E\"}, {\"status\": \"affected\", \"version\": \"15.2(3)E3\"}, {\"status\": \"affected\", \"version\": \"15.2(4)E1\"}, {\"status\": \"affected\", \"version\": \"15.2(2)E4\"}, {\"status\": \"affected\", \"version\": \"15.2(2)E5\"}, {\"status\": \"affected\", \"version\": \"15.2(4)E2\"}, {\"status\": \"affected\", \"version\": \"15.2(3)E4\"}, {\"status\": \"affected\", \"version\": \"15.2(5)E\"}, {\"status\": \"affected\", \"version\": \"15.2(4)E3\"}, {\"status\": \"affected\", \"version\": \"15.2(2)E6\"}, {\"status\": \"affected\", \"version\": \"15.2(5)E1\"}, {\"status\": \"affected\", \"version\": \"15.2(5b)E\"}, {\"status\": \"affected\", \"version\": \"15.2(2)E5a\"}, {\"status\": \"affected\", \"version\": \"15.2(2)E5b\"}, {\"status\": \"affected\", \"version\": \"15.2(4)E4\"}, {\"status\": \"affected\", \"version\": \"15.2(2)E7\"}, {\"status\": \"affected\", \"version\": \"15.2(5)E2\"}, {\"status\": \"affected\", \"version\": \"15.2(6)E\"}, {\"status\": \"affected\", \"version\": \"15.2(4)E5\"}, {\"status\": \"affected\", \"version\": \"15.2(2)E8\"}, {\"status\": \"affected\", \"version\": \"15.2(6)E0a\"}, {\"status\": \"affected\", \"version\": \"15.2(6)E1\"}, {\"status\": \"affected\", \"version\": \"15.2(6)E0c\"}, {\"status\": \"affected\", \"version\": \"15.2(4)E6\"}, {\"status\": \"affected\", \"version\": \"15.2(6)E2\"}, {\"status\": \"affected\", \"version\": \"15.2(2)E9\"}, {\"status\": \"affected\", \"version\": \"15.2(4)E7\"}, {\"status\": \"affected\", \"version\": \"15.2(7)E\"}, {\"status\": \"affected\", \"version\": \"15.2(2)E10\"}, {\"status\": \"affected\", \"version\": \"15.2(4)E8\"}, {\"status\": \"affected\", \"version\": \"15.2(6)E2a\"}, {\"status\": \"affected\", \"version\": \"15.2(6)E2b\"}, {\"status\": \"affected\", \"version\": \"15.2(7)E1\"}, {\"status\": \"affected\", \"version\": \"15.2(7)E0a\"}, {\"status\": \"affected\", \"version\": \"15.2(7)E0b\"}, {\"status\": \"affected\", \"version\": \"15.2(7)E0s\"}, {\"status\": \"affected\", \"version\": \"15.2(6)E3\"}, {\"status\": \"affected\", \"version\": \"15.2(4)E9\"}, {\"status\": \"affected\", \"version\": \"15.2(7)E2\"}, {\"status\": \"affected\", \"version\": \"15.2(7a)E0b\"}, {\"status\": \"affected\", \"version\": \"15.2(4)E10\"}, {\"status\": \"affected\", \"version\": \"15.2(7)E3\"}, {\"status\": \"affected\", \"version\": \"15.2(7)E1a\"}, {\"status\": \"affected\", \"version\": \"15.2(7b)E0b\"}, {\"status\": \"affected\", \"version\": \"15.2(7)E2a\"}, {\"status\": \"affected\", \"version\": \"15.2(4)E10a\"}, {\"status\": \"affected\", \"version\": \"15.2(7)E4\"}, {\"status\": \"affected\", \"version\": \"15.2(7)E3k\"}, {\"status\": \"affected\", \"version\": \"15.2(8)E\"}, {\"status\": \"affected\", \"version\": \"15.2(8)E1\"}, {\"status\": \"affected\", \"version\": \"15.2(7)E5\"}, {\"status\": \"affected\", \"version\": \"15.2(7)E6\"}, {\"status\": \"affected\", \"version\": \"15.2(8)E2\"}, {\"status\": \"affected\", \"version\": \"15.2(4)E10d\"}, {\"status\": \"affected\", \"version\": \"15.2(7)E7\"}, {\"status\": \"affected\", \"version\": \"15.2(8)E3\"}, {\"status\": \"affected\", \"version\": \"15.2(7)E8\"}, {\"status\": \"affected\", \"version\": \"15.2(8)E4\"}, {\"status\": \"affected\", \"version\": \"15.2(7)E9\"}, {\"status\": \"affected\", \"version\": \"15.2(8)E5\"}, {\"status\": \"affected\", \"version\": \"15.2(8)E6\"}, {\"status\": \"affected\", \"version\": \"15.2(7)E10\"}, {\"status\": \"affected\", \"version\": \"15.2(6)EB\"}, {\"status\": \"affected\", \"version\": \"15.2(4)EA7\"}, {\"status\": \"affected\", \"version\": \"15.2(4)EA8\"}, {\"status\": \"affected\", \"version\": \"15.2(4)EA9\"}, {\"status\": \"affected\", \"version\": \"15.2(4)EA9a\"}, {\"status\": \"affected\", \"version\": \"15.0(2)SQD\"}, {\"status\": \"affected\", \"version\": \"15.0(2)SQD1\"}, {\"status\": \"affected\", \"version\": \"15.0(2)SQD2\"}, {\"status\": \"affected\", \"version\": \"15.0(2)SQD3\"}, {\"status\": \"affected\", \"version\": \"15.0(2)SQD4\"}, {\"status\": \"affected\", \"version\": \"15.0(2)SQD5\"}, {\"status\": \"affected\", \"version\": \"15.0(2)SQD6\"}, {\"status\": \"affected\", \"version\": \"15.0(2)SQD7\"}, {\"status\": \"affected\", \"version\": \"15.0(2)SQD8\"}]}], \"exploits\": [{\"lang\": \"en\", \"value\": \"The Cisco Product Security Incident Response Team (PSIRT) is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory.\"}], \"references\": [{\"url\": \"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-c2960-3560-sboot-ZtqADrHq\", \"name\": \"cisco-sa-c2960-3560-sboot-ZtqADrHq\"}], \"descriptions\": [{\"lang\": \"en\", \"value\": \"A vulnerability in Cisco IOS Software for Cisco Catalyst 2960X, 2960XR, 2960CX, and 3560CX Series Switches could allow an authenticated, local attacker with privilege level 15 or an unauthenticated attacker with physical access to the device to execute persistent code at boot time and break the chain of trust.\\r\\n\\r This vulnerability is due to missing signature verification for specific files that may be loaded during the device boot process. An attacker could exploit this vulnerability by placing a crafted file into a specific location on an affected device. A successful exploit could allow the attacker to execute arbitrary code at boot time.\\r\\n\\r Because this allows the attacker to bypass a major security feature of the device, Cisco has raised the Security Impact Rating (SIR) of this advisory from Medium to High.\"}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"cwe\", \"cweId\": \"CWE-347\", \"description\": \"Improper Verification of Cryptographic Signature\"}]}], \"providerMetadata\": {\"orgId\": \"d1c1063e-7a18-46af-9102-31f8928bc633\", \"shortName\": \"cisco\", \"dateUpdated\": \"2025-05-07T17:35:31.850Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2025-20181\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2025-05-07T19:45:02.742Z\", \"dateReserved\": \"2024-10-10T19:15:13.225Z\", \"assignerOrgId\": \"d1c1063e-7a18-46af-9102-31f8928bc633\", \"datePublished\": \"2025-05-07T17:35:31.850Z\", \"assignerShortName\": \"cisco\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…