CVE-2025-20177
CVSS 3.1 Score 6.7 of 10 (medium)
Details
Summary
CVE-2025-20177 is a high-severity vulnerability affecting the boot process of Cisco IOS XR Software. This issue allows authenticated, local attackers with root-system privileges to bypass image signature verification and load unverified software on affected devices. The vulnerability arises from incomplete validation of files during the boot verification process, enabling attackers to manipulate system configuration options and bypass some integrity checks. Successful exploitation could result in the attacker controlling the boot configuration, permitting them to bypass the requirement for Cisco-signed images or modify the security properties of the running system.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Cisco IOS
Affected Vendors
- Cisco