CVE-2025-20145
CVSS 3.1 Score 5.8 of 10 (medium)
Details
Summary
CVE-2025-20145 is a vulnerability in the access control list (ACL) processing in the egress direction of Cisco IOS XR Software. This issue allows unauthenticated, remote attackers to bypass configured egress ACLs on affected devices. The flaw occurs when certain packets are mishandled during processing, with affected traffic received on an ingress interface on one line card and destined out of an egress interface on another line card. An exploit of this vulnerability could enable an attacker to bypass the egress ACL on the affected device. Cisco has released software updates to address this issue, and no workarounds are available.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Cisco IOS
Affected Vendors
- Cisco