CVE-2025-20142
CVSS 3.1 Score 8.6 of 10 (high)
Details
Summary
CVE-2025-20142 is a vulnerability affecting the IPv4 access control list (ACL) and quality of service (QoS) policy features of Cisco IOS XR Software on specific Cisco ASR routers. The flaw arises from the software's mishandling of malformed IPv4 packets, which can be exploited by unauthenticated, remote attackers to cause line cards to reset, leading to denial-of-service (DoS) conditions. Impacted devices process crafted IPv4 packets and may suffer from network processor errors, resulting in line card reloads and lost traffic. The vulnerability has predominantly been observed in Layer 2 VPN environments, but also affects Layer 3 configurations where an IPv4 ACL or QoS policy is applied.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Cisco IOS
Affected Vendors
- Cisco