CVE-2025-20143 is a medium-severity vulnerability in Cisco IOS XR Software that allows an authenticated, local attacker with root-system privileges to bypass Secure Boot and load unverified software. This is due to insufficient verification during the software load process, enabling an attacker to manipulate binaries and control the boot configuration. A successful exploit could allow the attacker to run unsigned images or alter system security properties. While no active exploits or public exploit code exist, the vulnerability has garnered some community discussion and media coverage, and Cisco has released software updates to address it.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.9.1CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xr:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.