Denial of Service Vulnerability in Cisco IOS XR Software
CVE-2025-20209
7.5HIGH
What is CVE-2025-20209?
A vulnerability exists in the Internet Key Exchange version 2 (IKEv2) function of Cisco IOS XR Software, which allows unauthenticated, remote attackers to disrupt the processing of control plane UDP packets. This occurs due to inadequate handling of malformed IKEv2 packets. An attacker can exploit this by sending such malformed packets, leading to a denial of service (DoS) condition on the affected device. Cisco has issued software updates to rectify this issue, as there are currently no viable workarounds available.
Affected Version(s)
Cisco IOS XR Software 6.5.3
Cisco IOS XR Software 6.6.1
Cisco IOS XR Software 6.5.2