Multicast Packet Handling Flaw in Cisco IOS XR Software for ASR 9000 and 9900 Series Routers
CVE-2025-20146
8.6HIGH
What is CVE-2025-20146?
A vulnerability in the Layer 3 multicast feature of Cisco IOS XR Software can be exploited by remote attackers to disrupt service on Cisco ASR 9000 and ASR 9900 Series Routers. The flaw arises from improper handling of malformed IPv4 multicast packets, which can lead to a line card reset, resulting in a denial of service condition. Attackers may send specifically crafted multicast traffic that triggers exceptions or a hard reset in affected line cards, causing temporary service interruptions as traffic is lost during reloads.
Affected Version(s)
Cisco IOS XR Software 7.11.1
Cisco IOS XR Software 7.9.21
Cisco IOS XR Software 7.10.2