CVE-2025-20191: Cisco NX-OS Software

High severity, CVSS 7.4. EPSS: 0.2% chance of exploitation in the next 30 days.

A vulnerability in the Switch Integrated Security Features (SISF) of Cisco IOS Software, Cisco IOS XE Software, Cisco NX-OS Software, and Cisco Wireless LAN Controller (WLC) AireOS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to the incorrect handling of DHCPv6 packets. An attacker could exploit this vulnerability by sending a crafted DHCPv6 packet to an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.

Affected products

  • Cisco Cisco NX-OS Software: version 8.2(5) only; version 7.3(5)D1(1) only; version 8.4(2) only; version 8.4(3) only; version 9.2(3) only; version 9.2(2v) only; …
  • Cisco Cisco Wireless Lan Controller Wlc: version 8.10.112.0 only; version 8.8.120.0 only; version 8.3.143.0 only; version 8.3.111.0 only; version 8.2.164.0 only; version 8.5.109.0 only; …

Published 2025-05-07. Last modified 2026-06-17.