Multicast Packet Handling Flaw in Cisco IOS XR Software for ASR 9000 and 9900 Series Routers
CVE-2025-20146
8.6HIGH
Summary
A vulnerability in the Layer 3 multicast feature of Cisco IOS XR Software can be exploited by remote attackers to disrupt service on Cisco ASR 9000 and ASR 9900 Series Routers. The flaw arises from improper handling of malformed IPv4 multicast packets, which can lead to a line card reset, resulting in a denial of service condition. Attackers may send specifically crafted multicast traffic that triggers exceptions or a hard reset in affected line cards, causing temporary service interruptions as traffic is lost during reloads.
Affected Version(s)
Cisco IOS XR Software 7.11.1
Cisco IOS XR Software 7.9.21
Cisco IOS XR Software 7.10.2
References
CVSS V3.1
Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved