Packet Handling Flaw in Cisco IOS XR Software by Cisco Systems
CVE-2025-20141
7.4HIGH
Summary
A flaw in the Cisco IOS XR Software allows unauthenticated adjacent attackers to manipulate packets, leading to control plane traffic failures across several Cisco IOS XR platforms. The issue arises from improper handling of specific packets punted to the route processor, particularly affecting the Linux stack on the device. By exploiting this vulnerability, an attacker can interrupt control plane operations, resulting in a denial of service (DoS) condition and impacting network reliability.
Affected Version(s)
Cisco IOS XR Software 7.9.2
References
CVSS V3.1
Score:
7.4
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved