Access Control Vulnerability in Cisco IOS XR Software
CVE-2025-20145
Summary
A vulnerability related to access control list (ACL) management in Cisco IOS XR Software could allow an unauthenticated remote attacker to bypass designated security controls. This issue arises from the improper handling of specific packets when received on one line card and destined out of another, where egress ACL rules are enforced. By exploiting this vulnerability, attackers can potentially manipulate traffic to circumvent security restrictions established by the egress ACL, leading to unauthorized access or data breaches. Cisco has released updates to rectify this issue, and users are strongly advised to implement these security patches.
Affected Version(s)
Cisco IOS XR Software 6.5.3
Cisco IOS XR Software 6.5.2
Cisco IOS XR Software 6.5.92
References
CVSS V3.1
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved