← CVE Tracker
7.4HIGH

CVE-2025-20311 — A vulnerability in the handling of certain Ethernet frames in Cisco IOS XE Software for Catalyst 9000…

Cisco · Ios Xe · Published 24 Sept 2025 · Modified 26 Sept 2026

Description

A vulnerability in the handling of certain Ethernet frames in Cisco IOS XE Software for Catalyst 9000 Series Switches could allow an unauthenticated, adjacent attacker to cause an egress port to become blocked and drop all outbound traffic. This vulnerability is due to improper handling of crafted Ethernet frames. An attacker could exploit this vulnerability by sending crafted Ethernet frames through an affected switch. A successful exploit could allow the attacker to cause the egress port to which the crafted frame is forwarded to start dropping all frames, resulting in a denial of service (DoS) condition.

References

What to do
  1. Check whether Ios Xe is in your asset inventory.
  2. Patch in the next maintenance window; prioritise internet-facing systems.
  3. Record the decision in your risk register for audit evidence.
Alert me on similar CVEs →
Share

Link: adminadda.com/cve/CVE-2025-20311