# CVE-2025-20327

## Summary

- **CVE ID:** CVE-2025-20327
- **Severity:** HIGH
- **CVSS Score:** 7.7 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H)
- **CWE:** CWE-1287
- **Published:** Sep 24, 2025
- **Last Modified:** Mar 12, 2026

## Description

A vulnerability in the web UI of Cisco IOS Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device.
 This vulnerability is due to improper input validation. An attacker could exploit this vulnerability by sending a crafted URL in an HTTP request. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.

## Affected Products

- Cisco — IOS (15.2(6)E2)
- Cisco — IOS (15.2(7)E)
- Cisco — IOS (15.2(6)E2a)
- Cisco — IOS (15.2(6)E2b)
- Cisco — IOS (15.2(7)E1)
- Cisco — IOS (15.2(7)E0a)
- Cisco — IOS (15.2(7)E0b)
- Cisco — IOS (15.2(7)E0s)
- Cisco — IOS (15.2(6)E3)
- Cisco — IOS (15.2(7)E2)
- Cisco — IOS (15.2(7a)E0b)
- Cisco — IOS (15.2(7)E3)
- Cisco — IOS (15.2(7)E1a)
- Cisco — IOS (15.2(7b)E0b)
- Cisco — IOS (15.2(7)E2a)
- Cisco — IOS (15.2(7)E4)
- Cisco — IOS (15.2(7)E3k)
- Cisco — IOS (15.2(8)E)
- Cisco — IOS (15.2(8)E1)
- Cisco — IOS (15.2(7)E5)
- Cisco — IOS (15.2(7)E6)
- Cisco — IOS (15.2(8)E2)
- Cisco — IOS (15.2(7)E7)
- Cisco — IOS (15.2(8)E3)
- Cisco — IOS (15.2(7)E8)
- Cisco — IOS (15.2(8)E4)
- Cisco — IOS (15.2(7)E9)
- Cisco — IOS (15.2(8)E5)
- Cisco — IOS (15.2(7)E10)

## References

- [CNA](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ios-invalid-url-dos-Nvxszf6u)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.38%
- **EPSS Percentile:** 31.1

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-09._