Denial of Service Vulnerability in Cisco IOS XR Software
CVE-2025-20340

7.4HIGH

Key Information:

Vendor

Cisco

Vendor
CVE Published:
10 September 2025

Badges

👾 Exploit Exists

What is CVE-2025-20340?

A vulnerability exists in the Address Resolution Protocol (ARP) implementation of Cisco IOS XR Software that could be exploited by an adjacent, unauthenticated attacker. This flaw allows an attacker to send excessive ARP traffic to the management interface of vulnerable devices, causing a broadcast storm. Such conditions can severely disrupt device performance, causing loss of management access and rendering the system completely unresponsive, thus leading to a denial of service scenario.

Affected Version(s)

Cisco IOS XR Software 6.5.3

Cisco IOS XR Software 6.5.29

Cisco IOS XR Software 6.5.1

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.