Denial of Service Vulnerability in Cisco IOS XR Software
CVE-2025-20209
7.5HIGH
Summary
A vulnerability exists in the Internet Key Exchange version 2 (IKEv2) function of Cisco IOS XR Software, which allows unauthenticated, remote attackers to disrupt the processing of control plane UDP packets. This occurs due to inadequate handling of malformed IKEv2 packets. An attacker can exploit this by sending such malformed packets, leading to a denial of service (DoS) condition on the affected device. Cisco has issued software updates to rectify this issue, as there are currently no viable workarounds available.
Affected Version(s)
Cisco IOS XR Software 6.5.3
Cisco IOS XR Software 6.6.1
Cisco IOS XR Software 6.5.2
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved