CVE-2025-20141

Cisco IOS XR Software Release 7.9.2 Denial of Service Vulnerabillity

Severity
High 7.4
CVSS 3.1
Adjacent, local or physical access what this means
Exploited
Not listed
EPSS
0.002
13.3th percentile
Discovered by
Vendor
Vendor-published field
Published
Mar 12, 2025
Assigned by cisco

Description

A vulnerability in the handling of specific packets that are punted from a line card to a route processor in Cisco IOS XR Software Release 7.9.2 could allow an unauthenticated, adjacent attacker to cause control plane traffic to stop working on multiple Cisco IOS XR platforms.  This vulnerability is due to incorrect handling of packets that are punted to the route processor. An attacker could exploit this vulnerability by sending traffic, which must be handled by the Linux stack on the route processor, to an affected device. A successful exploit could allow the attacker to cause control plane traffic to stop working, resulting in a denial of service (DoS) condition.

Weakness: CWE-770

Affected products

Vendor Product Category Matched by
Cisco Cisco IOS XR Software Routing & Switching cna-assigner
Vendor-reported products (1)
  • Cisco · Cisco IOS XR Software

Vendor advisory

cisco-sa-xr792-bWfVDPY

Cisco IOS XR Software Release 7.9.2 Denial of Service Vulnerability

Cisco’s rating: High (advisory CVSS 7.4) · Published Mar 12, 2025

Bug ID: CSCwf89955

The vendor’s rating applies to the whole advisory and can differ from this CVE’s own CVSS severity. Where this comes from

Something wrong here?