CVE-2025-20143
CVSS 3.1 Score 6.7 of 10 (medium)
Details
Summary
CVE-2025-20143 is a vulnerability impacting the boot process of Cisco IOS XR Software that enables authenticated, high-privileged attackers to bypass Secure Boot functionality and load unverified software on affected devices. This vulnerability stems from insufficient module verification during the software load process. By manipulating loaded binaries, an attacker can bypass certain integrity checks during the boot process, potentially controlling the boot configuration and bypassing the requirement for Cisco-signed images or altering the system's security properties. The Secure Boot feature itself is not affected by this issue, but Cisco has released software updates to address this vulnerability. No workarounds are available.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Cisco IOS
Affected Vendors
- Cisco