THREAT OPS › Threat News › [NVD] CVE-2025-20313 (MEDIUM 6.7) — Multiple vulnerabilities in Cisco IOS XE Software of could allow an authenticated, local attacker with level-15 privileges or an unauthenticated attacker with physical access to the device to execute persistent code at boot time and break the chain of trust.
These vulnerabilit
[NVD] CVE-2025-20313 (MEDIUM 6.7) — Multiple vulnerabilities in Cisco IOS XE Software of could allow an authenticated, local attacker with level-15 privileges or an unauthenticated attacker with physical access to the device to execute persistent code at boot time and break the chain of trust. These vulnerabilit
CVE-2025-20313 CVSS: 6.7 MEDIUM Published: 2025-09-24T18:15:35.530
Multiple vulnerabilities in Cisco IOS XE Software of could allow an authenticated, local attacker with level-15 privileges or an unauthenticated attacker with physical access to the device to execute persistent code at boot time and break the chain of trust. These vulnerabilities are due path traversal and improper image integr
MITRE ATT&CK techniques
- VulnerabilitiesT1588.006
Indicators of compromise
- CVE-2025-20313cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-20313