Cisco IOS XE Catalyst 9000 Ethernet Frame DoS via Crafted Frames
CVE-2025-20311 Published on September 24, 2025
A vulnerability in the handling of certain Ethernet frames in Cisco IOS XE Software for Catalyst 9000 Series Switches could allow an unauthenticated, adjacent attacker to cause an egress port to become blocked and drop all outbound traffic. This vulnerability is due to improper handling of crafted Ethernet frames. An attacker could exploit this vulnerability by sending crafted Ethernet frames through an affected switch. A successful exploit could allow the attacker to cause the egress port to which the crafted frame is forwarded to start dropping all frames, resulting in a denial of service (DoS) condition.
Vulnerability Analysis
Weakness Type
Data Processing Errors
Weaknesses in this category are typically found in functionality that processes data. Data processing is the manipulation of input to retrieve or save information.
Products Associated with CVE-2025-20311
Want to know whenever a new CVE is published for Cisco IOS XE? stack.watch will email you.
Affected Versions
Cisco IOS XE Software:- Version 16.6.1 is affected.
- Version 16.6.2 is affected.
- Version 16.6.3 is affected.
- Version 16.6.4 is affected.
- Version 16.6.5 is affected.
- Version 16.6.4a is affected.
- Version 16.6.6 is affected.
- Version 16.6.7 is affected.
- Version 16.6.8 is affected.
- Version 16.6.9 is affected.
- Version 16.6.10 is affected.
- Version 16.7.1 is affected.
- Version 16.8.1 is affected.
- Version 16.8.1a is affected.
- Version 16.8.1s is affected.
- Version 16.9.1 is affected.
- Version 16.9.2 is affected.
- Version 16.9.1s is affected.
- Version 16.9.3 is affected.
- Version 16.9.4 is affected.
- Version 16.9.5 is affected.
- Version 16.9.6 is affected.
- Version 16.9.7 is affected.
- Version 16.9.8 is affected.
- Version 16.10.1 is affected.
- Version 16.10.1s is affected.
- Version 16.10.1e is affected.
- Version 16.11.1 is affected.
- Version 16.11.1b is affected.
- Version 16.11.1s is affected.
- Version 16.12.1 is affected.
- Version 16.12.1s is affected.
- Version 16.12.1c is affected.
- Version 16.12.2 is affected.
- Version 16.12.3 is affected.
- Version 16.12.8 is affected.
- Version 16.12.2s is affected.
- Version 16.12.4 is affected.
- Version 16.12.3s is affected.
- Version 16.12.3a is affected.
- Version 16.12.4a is affected.
- Version 16.12.5 is affected.
- Version 16.12.6 is affected.
- Version 16.12.5b is affected.
- Version 16.12.6a is affected.
- Version 16.12.7 is affected.
- Version 16.12.14 is affected.
- Version 17.1.1 is affected.
- Version 17.1.1s is affected.
- Version 17.1.1t is affected.
- Version 17.1.3 is affected.
- Version 17.2.1 is affected.
- Version 17.2.1a is affected.
- Version 17.3.1 is affected.
- Version 17.3.2 is affected.
- Version 17.3.3 is affected.
- Version 17.3.2a is affected.
- Version 17.3.4 is affected.
- Version 17.3.5 is affected.
- Version 17.3.6 is affected.
- Version 17.3.4b is affected.
- Version 17.3.7 is affected.
- Version 17.3.8 is affected.
- Version 17.3.8a is affected.
- Version 17.4.1 is affected.
- Version 17.5.1 is affected.
- Version 17.6.1 is affected.
- Version 17.6.2 is affected.
- Version 17.6.3 is affected.
- Version 17.6.1y is affected.
- Version 17.6.4 is affected.
- Version 17.6.5 is affected.
- Version 17.6.6 is affected.
- Version 17.6.6a is affected.
- Version 17.6.5a is affected.
- Version 17.6.7 is affected.
- Version 17.6.8 is affected.
- Version 17.7.1 is affected.
- Version 17.10.1 is affected.
- Version 17.10.1b is affected.
- Version 17.8.1 is affected.
- Version 17.9.1 is affected.
- Version 17.9.2 is affected.
- Version 17.9.3 is affected.
- Version 17.9.4 is affected.
- Version 17.9.5 is affected.
- Version 17.9.4a is affected.
- Version 17.9.6 is affected.
- Version 17.9.6a is affected.
- Version 17.11.1 is affected.
- Version 17.12.1 is affected.
- Version 17.12.2 is affected.
- Version 17.12.3 is affected.
- Version 17.12.4 is affected.
- Version 17.12.1z3 is affected.
- Version 17.13.1 is affected.
- Version 17.14.1 is affected.
- Version 17.11.99SW is affected.
- Version 17.15.1 is affected.
- Version 17.15.2 is affected.
- Version 17.15.2a is affected.
- Version 17.15.2b is affected.
- Version 17.16.1 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.