#VU105677 Input validation error in Cisco IOS XR - CVE-2025-20142
Published: March 12, 2025
Cisco IOS XR
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input in the IPv4 access control list (ACL) feature and quality of service (QoS) policy feature. A remote attacker can send specially crafted IPv4 unicast packets to the system and perform a denial of service (DoS) attack.
This vulnerability affects the following Cisco
products if they are running a vulnerable release of Cisco IOS XR 64-bit
Software and have a vulnerable configuration enabled for any of the
installed line cards: