Remote Code Execution Vulnerability in Cisco IOS XR Software on ASR 9000 and ASR 9900 Series Routers
CVE-2025-20142
Summary
The vulnerability affects Cisco IOS XR Software, enabling unauthenticated remote attackers to exploit malformed IPv4 packets. This can lead to a line card reset and result in a Denial of Service condition. Primarily observed in Layer 2 VPN environments, this flaw arises when an IPv4 access control list (ACL) or quality of service (QoS) policy is applied. Attackers can cause network processor errors, leading to the loss of traffic as the line card reloads. The risk extends to both Layer 2 and Layer 3 configurations, emphasizing the importance of safeguarding network infrastructure against such exploits.
Affected Version(s)
Cisco IOS XR Software 7.1.15
Cisco IOS XR Software 7.1.2
Cisco IOS XR Software 6.7.2
References
CVSS V3.1
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved