CVE-2025-20146

CVSS 3.1 Score 8.6 of 10 (high)

Details

Published Mar 12, 2025
CWE ID 20

Summary

CVE-2025-20146 is a vulnerability affecting Cisco IOS XR Software on certain ASR series routers. This issue arises due to the software's mishandling of malformed IPv4 multicast packets. An unauthenticated, remote attacker can take advantage of this flaw by sending crafted multicast packets to an affected device, leading to line card exceptions or even a hard reset. This DoS condition occurs when interfaces have either an IPv4 access control list or a QoS policy applied, causing traffic on the affected line card to be lost while it reloads.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share