CVE-2025-20221

A vulnerability in the packet filtering features of Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to bypass Layer 3 and Layer 4 traffic filters. 

 This vulnerability is due to improper traffic filtering conditions on an affected device. An attacker could exploit this vulnerability by sending a crafted packet to the affected device. A successful exploit could allow the attacker to bypass the Layer 3 and Layer 4 traffic filters and inject a crafted packet into the network.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
ciscoCNA
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 3%
VendorProductVersion
ciscoios_xe
16.12.13
ciscoios_xe
17.1.1
ciscoios_xe
17.1.1s:s
ciscoios_xe
17.1.1t:t
ciscoios_xe
17.1.3
ciscoios_xe
17.2.1
ciscoios_xe
17.2.1a:a
ciscoios_xe
17.2.1r:r
ciscoios_xe
17.2.1v:v
ciscoios_xe
17.2.2
ciscoios_xe
17.2.3
ciscoios_xe
17.3.1
ciscoios_xe
17.3.1a:a
ciscoios_xe
17.3.2
ciscoios_xe
17.3.2a:a
ciscoios_xe
17.3.3
ciscoios_xe
17.3.4
ciscoios_xe
17.3.4a:a
ciscoios_xe
17.3.5
ciscoios_xe
17.3.6
ciscoios_xe
17.3.7
ciscoios_xe
17.3.8
ciscoios_xe
17.3.8a:a
ciscoios_xe
17.4.1
ciscoios_xe
17.4.1a:a
ciscoios_xe
17.4.1b:b
ciscoios_xe
17.4.2
ciscoios_xe
17.5.1
ciscoios_xe
17.5.1a:a
ciscoios_xe
17.6.1
ciscoios_xe
17.6.1a:a
ciscoios_xe
17.6.1y:y
ciscoios_xe
17.6.2
ciscoios_xe
17.6.3
ciscoios_xe
17.6.3a:a
ciscoios_xe
17.6.4
ciscoios_xe
17.6.5
ciscoios_xe
17.6.5a:a
ciscoios_xe
17.6.6
ciscoios_xe
17.6.6a:a
ciscoios_xe
17.6.7
ciscoios_xe
17.6.8
ciscoios_xe
17.6.8a:a
ciscoios_xe
17.7.1
ciscoios_xe
17.7.1a:a
ciscoios_xe
17.7.2
ciscoios_xe
17.8.1
ciscoios_xe
17.8.1a:a
ciscoios_xe
17.9.1
ciscoios_xe
17.9.1a:a
ciscoios_xe
17.9.2
ciscoios_xe
17.9.2a:a
ciscoios_xe
17.9.3
ciscoios_xe
17.9.3a:a
ciscoios_xe
17.9.4
ciscoios_xe
17.9.4a:a
ciscoios_xe
17.9.5
ciscoios_xe
17.9.5a:a
ciscoios_xe
17.9.5b:b
ciscoios_xe
17.9.5e:e
ciscoios_xe
17.9.5f:f
ciscoios_xe
17.9.6
ciscoios_xe
17.9.6a:a
ciscoios_xe
17.10.1
ciscoios_xe
17.10.1a:a
ciscoios_xe
17.10.1b:b
ciscoios_xe
17.11.1
ciscoios_xe
17.11.1a:a
ciscoios_xe
17.12.1
ciscoios_xe
17.12.1a:a
ciscoios_xe
17.12.1z2:z2
ciscoios_xe
17.12.2
ciscoios_xe
17.12.3
ciscoios_xe
17.12.3a:a
ciscoios_xe
17.12.4
ciscoios_xe
17.12.4a:a
ciscoios_xe
17.12.4b:b
ciscoios_xe
17.13.1
ciscoios_xe
17.13.1a:a
ciscoios_xe
17.14.1
ciscoios_xe
17.14.1a:a
ciscoios_xe
17.15.1
ciscoios_xe
17.15.1a:a
ciscoios_xe
17.15.1x:x
ciscoios_xe
17.15.2
ciscoios_xe
17.15.2b:b
ciscoios_xe
17.15.2c:c
ciscoios_xe
17.16.1
ciscoios_xe
17.16.1a:a
𝑥
= Vulnerable software versions