Remote Code Execution Vulnerability in Cisco IOS XR Software on ASR 9000 and ASR 9900 Series Routers
CVE-2025-20142

8.6HIGH

Key Information:

Vendor
Cisco
Vendor
CVE Published:
12 March 2025

Badges

👾 Exploit Exists

Summary

The vulnerability affects Cisco IOS XR Software, enabling unauthenticated remote attackers to exploit malformed IPv4 packets. This can lead to a line card reset and result in a Denial of Service condition. Primarily observed in Layer 2 VPN environments, this flaw arises when an IPv4 access control list (ACL) or quality of service (QoS) policy is applied. Attackers can cause network processor errors, leading to the loss of traffic as the line card reloads. The risk extends to both Layer 2 and Layer 3 configurations, emphasizing the importance of safeguarding network infrastructure against such exploits.

Affected Version(s)

Cisco IOS XR Software 7.1.15

Cisco IOS XR Software 7.1.2

Cisco IOS XR Software 6.7.2

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.