CVE-2025-20146
CVSS 3.1 Score 8.6 of 10 (high)
Details
Published Mar 12, 2025
CWE ID 20
Summary
CVE-2025-20146 is a vulnerability affecting Cisco IOS XR Software on certain ASR series routers. This issue arises due to the software's mishandling of malformed IPv4 multicast packets. An unauthenticated, remote attacker can take advantage of this flaw by sending crafted multicast packets to an affected device, leading to line card exceptions or even a hard reset. This DoS condition occurs when interfaces have either an IPv4 access control list or a QoS policy applied, causing traffic on the affected line card to be lost while it reloads.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Cisco IOS
Affected Vendors
- Cisco