CVE-2025-20142

CVSS 3.1 Score 8.6 of 10 (high)

Details

Published Mar 12, 2025
CWE ID 20

Summary

CVE-2025-20142 is a vulnerability affecting the IPv4 access control list (ACL) and quality of service (QoS) policy features of Cisco IOS XR Software on specific Cisco ASR routers. The flaw arises from the software's mishandling of malformed IPv4 packets, which can be exploited by unauthenticated, remote attackers to cause line cards to reset, leading to denial-of-service (DoS) conditions. Impacted devices process crafted IPv4 packets and may suffer from network processor errors, resulting in line card reloads and lost traffic. The vulnerability has predominantly been observed in Layer 2 VPN environments, but also affects Layer 3 configurations where an IPv4 ACL or QoS policy is applied.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share