CVE-2025-20115

CVSS 3.1 Score 8.6 of 10 (high)

Details

Published Mar 12, 2025
CWE ID 120

Summary

CVE-2025-20115 is a denial-of-service vulnerability affecting the Confederation implementation for Border Gateway Protocol (BGP) in Cisco IOS XR Software. This issue stemms from a memory corruption occurring when processing a BGP update message with an AS_CONFED_SEQUENCE attribute containing 255 Autonomous System Numbers (ASNs). An unauthenticated, remote attacker can exploit this vulnerability by sending a maliciously crafted update or by designing the network to generate an AS_CONFED_SEQUENCE attribute exceeding 255 ASNs. Successful exploitation may result in memory corruption, causing the BGP process to restart, leading to a denial-of-service condition. Confederation speakers within the same autonomous system or networks with AS_CONFED_SEQUENCE attributes surpassing 255 ASNs are at risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share