CVE-2025-20141 is a denial-of-service vulnerability affecting Cisco IOS XR Software Release 7.9.2, specifically impacting multiple Cisco IOS XR platforms. It stems from incorrect handling of packets punted from a line card to a route processor. The vulnerability has a CVSS score of 7.4 (High), indicating an unauthenticated, adjacent attacker can exploit it with low complexity by sending specific traffic, leading to a complete cessation of control plane traffic. This results in a denial of service. There is no evidence of active exploitation, nor is public exploit code available (Metasploit, Nuclei, ExploitDB). While there's limited community discussion (1 mention), it has garnered some media attention with one article from SecurityWeek.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.9.2CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xr:7.9.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.