Denial of Service Vulnerability in Cisco IOS XR Software
CVE-2025-20209

7.5HIGH

Key Information:

Vendor
Cisco
Vendor
CVE Published:
12 March 2025

Badges

👾 Exploit Exists

Summary

A vulnerability exists in the Internet Key Exchange version 2 (IKEv2) function of Cisco IOS XR Software, which allows unauthenticated, remote attackers to disrupt the processing of control plane UDP packets. This occurs due to inadequate handling of malformed IKEv2 packets. An attacker can exploit this by sending such malformed packets, leading to a denial of service (DoS) condition on the affected device. Cisco has issued software updates to rectify this issue, as there are currently no viable workarounds available.

Affected Version(s)

Cisco IOS XR Software 6.5.3

Cisco IOS XR Software 6.6.1

Cisco IOS XR Software 6.5.2

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.