PT-2025-11097 · Cisco · Cisco Ios Xr

CVE-2025-20141

·

Publicado

2024-09-02

·

Atualizado

2025-08-06

CVSS v3.1

7.4

Alta

VetorAV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Cisco IOS XR Software version 7.9.2
Description: A vulnerability in the handling of specific packets that are punted from a line card to a route processor could allow an unauthenticated, adjacent attacker to cause control plane traffic to stop working on multiple Cisco IOS XR platforms. This issue is due to incorrect handling of packets that are punted to the route processor. An attacker could exploit this by sending traffic, which must be handled by the Linux stack on the route processor, to an affected device. A successful exploit could allow the attacker to cause control plane traffic to stop working, resulting in a denial of service (DoS) condition.
Recommendations: For Cisco IOS XR Software version 7.9.2, consider applying a patch or update to fix the issue with handling specific packets punted from a line card to a route processor. As a temporary workaround, restrict access to the route processor to minimize the risk of exploitation. Avoid sending traffic that must be handled by the Linux stack on the route processor to the affected device until the issue is resolved.

Correção

DoS

Allocation of Resources Without Limits

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-02696
CVE-2025-20141

Produtos afetados

Cisco Ios Xr