CVE-2025-20209
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Mar 12, 2025
CWE ID 770
Summary
CVE-2025-20209 is a vulnerability affecting the Internet Key Exchange version 2 (IKEv2) function in Cisco IOS XR Software. Malformed IKEv2 packets can be exploited by unauthenticated, remote attackers, leading to the prevention of an affected device from processing any control plane UDP packets. This results in a denial of service (DoS) condition. The vulnerability stems from improper packet handling. Cisco has released software updates to mitigate this issue, and currently, no workarounds are available.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Cisco IOS
Affected Vendors
- Cisco