Cisco IOS Software for Cisco Catalyst 2960X, 2960XR, 2960CX, and 3560CX Series Switches Secure Boot Bypass Vulnerability

🚨 SEVERITY: MEDIUM — CVSS 6.8 Security Advisory

TL;DR 📌

A medium-severity vulnerability has been identified in Cisco IOS Software for Catalyst 2960X, 2960XR, 2960CX, and 3560CX Series Switches. This vulnerability allows an attacker to bypass secure boot protections, potentially executing arbitrary code at boot time. Cisco has released software updates to address this issue, and no workarounds are available.

What happened 🕵️‍♂️

A vulnerability in Cisco IOS Software affects Catalyst 2960X, 2960XR, 2960CX, and 3560CX Series Switches. This flaw allows an authenticated local attacker with privilege level 15 or an unauthenticated attacker with physical access to execute persistent code during the boot process, effectively breaking the device’s chain of trust. The vulnerability arises from missing signature verification for certain files loaded during boot. Cisco has raised the Security Impact Rating (SIR) from Medium to High due to the potential severity of this issue.

Affected products 🖥️

The following Cisco products are affected if they are running a vulnerable release of Cisco IOS Software:

  • Catalyst 2960X Series Switches
  • Catalyst 2960XR Series Switches
  • Catalyst 2960CX Series Switches
  • Catalyst 3560CX Series Switches

Fixed software 🔧

Upgrade to at least the first fixed release in your train (or later):

Product / Release Train First Fixed Release Notes
ISE / ISE-PIC 1.0 Initial public release.

Workarounds 🧯

There are no workarounds available to mitigate this vulnerability.

Risk in context 🎯

With a CVSS score of 6.8, this vulnerability is classified as Medium severity. However, due to the nature of the exploit—allowing arbitrary code execution at boot—it poses a significant risk to the integrity and security of affected devices. Organizations should prioritize applying the available software updates to protect against potential exploitation.

Fast facts ⚡

  • Vulnerability ID: CVE-2025-20181
  • CVSS Score: 6.8 (Medium)
  • Affected Products: Catalyst 2960X, 2960XR, 2960CX, and 3560CX Series Switches
  • Status: Final advisory
  • Workarounds: None available
  • Fixed Software: Updates available, specific versions not listed

For leadership 🧭

Executive summary. Affected Catalyst 2960X, 2960XR, 2960CX and 3560CX switches can have their secure boot chain of trust broken by a privilege-15 local user or anyone with physical access, allowing persistent boot-time code. There is no workaround, so patching is the only fix and should be scheduled promptly rather than treated as routine maintenance.

Why it matters:

  • The flaw lets code run at boot time on the switch itself, before normal IOS protections apply, so it can persist across reboots and reimaging attempts
  • Exploitation requires either privilege level 15 access or physical access to the device, meaning console rooms, wiring closets and admin credential hygiene around these switches matter directly
  • Cisco raised its own Security Impact Rating from Medium to High despite the 6.8 CVSS score, reflecting the seriousness of a broken boot chain of trust on network infrastructure
  • No workaround exists, so any Catalyst 2960X, 2960XR, 2960CX or 3560CX switch left unpatched remains exposed indefinitely

Now / Next / Later:

  • Now: Identify every Catalyst 2960X, 2960XR, 2960CX and 3560CX switch in the estate and confirm which IOS release each is running.
  • Next: Schedule and apply the Cisco-fixed IOS release to each affected switch in the next maintenance window, since no interim workaround exists.
  • Later: Tighten physical access controls to switch console and USB ports and review who holds privilege level 15 on these devices to reduce the chance of boot-time tampering going forward.