Denial of Service Vulnerability in Cisco IOS XR Software
CVE-2025-20340
7.4HIGH
What is CVE-2025-20340?
A vulnerability exists in the Address Resolution Protocol (ARP) implementation of Cisco IOS XR Software that could be exploited by an adjacent, unauthenticated attacker. This flaw allows an attacker to send excessive ARP traffic to the management interface of vulnerable devices, causing a broadcast storm. Such conditions can severely disrupt device performance, causing loss of management access and rendering the system completely unresponsive, thus leading to a denial of service scenario.
Affected Version(s)
Cisco IOS XR Software 6.5.3
Cisco IOS XR Software 6.5.29
Cisco IOS XR Software 6.5.1