CVE-2025-20115
published 2025-03-12CVE-2025-20115: A vulnerability in confederation implementation for the Border Gateway Protocol (BGP) in Cisco IOS XR Software could allow an unauthenticated, remote attacker…
PriorityP351high8.6CVSS 3.1
AVNACLPRNUINSCCNINAH
EPSS
0.92%
56.1th percentile
A vulnerability in confederation implementation for the Border Gateway Protocol (BGP) in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
This vulnerability is due to a memory corruption that occurs when a BGP update is created with an AS_CONFED_SEQUENCE attribute that has 255 autonomous system numbers (AS numbers). An attacker could exploit this vulnerability by sending a crafted BGP update message, or the network could be designed in such a manner that the AS_CONFED_SEQUENCE attribute grows to 255 AS numbers or more. A successful exploit could allow the attacker to cause memory corruption, which may cause the BGP process to restart, resulting in a DoS condition. To exploit this vulnerability, an attacker must control a BGP confederation speaker within the same autonomous system as the victim, or the network must be designed in such a manner that the AS_CONFED_SEQUENCE attribute grows to 255 AS numbers or more.
Affected
187 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
CVSS provenance
nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
vendor_cisco8.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS XR Software Border Gateway Protocol Confederation Denial of Service Vulnerability
vendor_cisco·2025-03-12·CVSS 8.6
CVE-2025-20115 [HIGH] CWE-120 Cisco IOS XR Software Border Gateway Protocol Confederation Denial of Service Vulnerability
Cisco IOS XR Software Border Gateway Protocol Confederation Denial of Service Vulnerability
A vulnerability in confederation implementation for the Border Gateway Protocol (BGP) in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
This vulnerability is due to a memory corruption that occurs when a BGP update is created with an AS_CONFED_SEQUENCE attribute that has 255 autonomous system numbers (AS numbers). An attacker could exploit this vulnerability by sending a crafted BGP update message, or the network could be designed in such a manner that the AS_CONFED_SEQUENCE attribute grows to 255 AS numbers or more. A successful exploit could allow the attacker to cause memory corruption, which may cause the BGP process to resta
Cisco
Cisco IOS XR Software Border Gateway Protocol Confederation Denial of Service Vulnerability
vendor_cisco·CVSS 3.1
CVE-2025-20115 Cisco IOS XR Software Border Gateway Protocol Confederation Denial of Service Vulnerability
CVE-2025-20115: Cisco IOS XR Software Border Gateway Protocol Confederation Denial of Service Vulnerability
A vulnerability in confederation implementation for the Border Gateway Protocol (BGP) in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to a memory corruption that occurs when a BGP update is created with an AS_CONFED_SEQUENCE attribute that has 255 autonomous system numbers (AS numbers). An attacker could exploit this vulnerability by sending a crafted BGP update message, or the network could be designed in such a manner that the AS_CONFED_SEQUENCE attribute grows to 255 AS numbers or more. A successful exploit could allow the attacker to cause memory corruption, which may cause the BGP pr
GHSA
GHSA-rp6p-7xx7-cr6f: A vulnerability in confederation implementation for the Border Gateway Protocol (BGP) in Cisco IOS XR Software could allow an unauthenticated, remote
ghsa_unreviewed·2025-03-12
CVE-2025-20115 [HIGH] CWE-120 GHSA-rp6p-7xx7-cr6f: A vulnerability in confederation implementation for the Border Gateway Protocol (BGP) in Cisco IOS XR Software could allow an unauthenticated, remote
A vulnerability in confederation implementation for the Border Gateway Protocol (BGP) in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
This vulnerability is due to a memory corruption that occurs when a BGP update is created with an AS_CONFED_SEQUENCE attribute that has 255 autonomous system numbers (AS numbers). An attacker could exploit this vulnerability by sending a crafted BGP update message, or the network could be designed in such a manner that the AS_CONFED_SEQUENCE attribute grows to 255 AS numbers or more. A successful exploit could allow the attacker to cause memory corruption, which may cause the BGP process to restart, resulting in a DoS condition. To exploit this vulnerability, an attacker must control a B
No detection rules found.
No public exploits indexed.
Bleepingcomputer
New Cisco DoS flaw requires manual reboot to revive devices
blogs_bleepingcomputer·2026-05-06·CVSS 9.9
CVE-2026-20188 [CRITICAL] New Cisco DoS flaw requires manual reboot to revive devices
## New Cisco DoS flaw requires manual reboot to revive devices
## Sergiu Gatlan
Cisco released security updates to fix a Crosswork Network Controller (CNC) and Network Services Orchestrator (NSO) denial-of-service (DoS) vulnerability that requires manually rebooting targeted systems for recovery.
Large enterprises and service providers leverage the CNC software suite to simplify multivendor network management and operations handling with automation, while the NSO orchestration platform helps them manage network devices and resources.
Tracked as CVE-2026-20188 , this high-severity security flaw stems from inadequate rate limiting on incoming network connections and can be exploited remotely by unauthenticated threat actors to crash unpatched Cisco CNC and Cisco NSO systems through low-c
Bleepingcomputer
Cisco IOS XR vulnerability lets attackers crash BGP on routers
blogs_bleepingcomputer·2025-03-14·CVSS 8.6
CVE-2025-20115 [HIGH] Cisco IOS XR vulnerability lets attackers crash BGP on routers
## Cisco IOS XR vulnerability lets attackers crash BGP on routers
## Sergiu Gatlan
Cisco has patched a denial of service (DoS) vulnerability that lets attackers crash the Border Gateway Protocol (BGP) process on IOS XR routers with a single BGP update message.
IOS XR runs on the company's carrier-grade, Network Convergence System (NCS), and Carrier Routing System (CRS) series of routers, such as the ASR 9000, NCS 5500, and 8000 series.
This high-severity flaw (tracked as CVE-2025-20115 ) was found in the confederation implementation for the Border Gateway Protocol (BGP), and it only affects Cisco IOS XR devices if BGP confederation is configured.
Successful exploitation allows unauthenticated attackers to take down vulnerable devices remotely in low-complexity attacks by causing memor
2025-03-12
Published