CVE-2025-20142

Severity
8.6HIGH
EPSS
0.3%
top 44.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 12

Description

A vulnerability in the IPv4 access control list (ACL) feature and quality of service (QoS) policy feature of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers, ASR 9902 Compact High-Performance Routers, and ASR 9903 Compact High-Performance Routers could allow an unauthenticated, remote attacker to cause a line card to reset, resulting in a denial of service (DoS) condition. This vulnerability is due to the incorrect handling of malformed IPv4 packets that are receive

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:HExploitability: 3.9 | Impact: 4.0

Affected Packages2 packages

CVEListV5cisco/cisco_ios_xr_software34 versions+33
NVDcisco/ios_xr34 versions+33

🔴Vulnerability Details

2
CVEList
Cisco IOS XR Software for ASR 9000 Series Routers L2VPN Denial of Service Vulnerability2025-03-12
GHSA
GHSA-w9ff-5p26-w67v: A vulnerability in the IPv4 access control list (ACL) feature and quality of service (QoS) policy feature of Cisco IOS XR Software for Cisco ASR 90002025-03-12

📋Vendor Advisories

1
Cisco
Cisco IOS XR Software for ASR 9000 Series Routers IPv4 Unicast Packets Denial of Service Vulnerability2025-03-12