CVE-2025-20141 Information

Description

A vulnerability in the handling of specific packets that are punted from a line card to a route processor in Cisco IOS XR Software Release 7.9.2 could allow an unauthenticated adjacent attacker to cause control plane traffic to stop working on multiple Cisco IOS XR platforms. 

This vulnerability is due to incorrect handling of packets that are punted to the route processor. An attacker could exploit this vulnerability by sending traffic which must be handled by the Linux stack on the route processor to an affected device. A successful exploit could allow the attacker to cause control plane traffic to stop working resulting in a denial of service (DoS) condition.

CVSS Vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Reference

https://blog.apnic.net/2024/09/02/crafting-endless-as-paths-in-bgp/ https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-xr792-bWfVDPY

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

CHANGED

Integrity Impact

NONE

Availability Impact

NONE

Base Score

HIGH

Base Severity

7.4

Share on: