CVE-2025-20143

CVSS 3.1 Score 6.7 of 10 (medium)

Details

Published Mar 12, 2025
CWE ID 347

Summary

CVE-2025-20143 is a vulnerability impacting the boot process of Cisco IOS XR Software that enables authenticated, high-privileged attackers to bypass Secure Boot functionality and load unverified software on affected devices. This vulnerability stems from insufficient module verification during the software load process. By manipulating loaded binaries, an attacker can bypass certain integrity checks during the boot process, potentially controlling the boot configuration and bypassing the requirement for Cisco-signed images or altering the system's security properties. The Secure Boot feature itself is not affected by this issue, but Cisco has released software updates to address this vulnerability. No workarounds are available.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share