Access Control Vulnerability in Cisco IOS XR Software
CVE-2025-20145

5.8MEDIUM

Key Information:

Vendor
Cisco
Vendor
CVE Published:
12 March 2025

Badges

👾 Exploit Exists

Summary

A vulnerability related to access control list (ACL) management in Cisco IOS XR Software could allow an unauthenticated remote attacker to bypass designated security controls. This issue arises from the improper handling of specific packets when received on one line card and destined out of another, where egress ACL rules are enforced. By exploiting this vulnerability, attackers can potentially manipulate traffic to circumvent security restrictions established by the egress ACL, leading to unauthorized access or data breaches. Cisco has released updates to rectify this issue, and users are strongly advised to implement these security patches.

Affected Version(s)

Cisco IOS XR Software 6.5.3

Cisco IOS XR Software 6.5.2

Cisco IOS XR Software 6.5.92

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.