Improper Verification of Cryptographic Signature in Cisco IOS XR - CVE-2025-20143

 

Improper Verification of Cryptographic Signature in Cisco IOS XR - CVE-2025-20143

Published: March 12, 2025


Vulnerability identifier: #VU105678
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-20143
CWE-ID: CWE-347
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to bypass security boot protections.

The vulnerability exists due to improper cryptographic signature verification of modules in the software load process. A local user can bypass some of the integrity checks that are performed during the booting process and compromise the affected system.

This vulnerability affects the following Cisco products if they are running a vulnerable release of Cisco IOS XR Software, regardless of device configuration:

  • ASR 9000 Series Aggregation Services Routers (64-bit)
  • IOS XRv 9000 Routers
  • Network Convergence System (NCS) 540 Series Routers that are running an NCS540-iosxr base image
  • NCS 560 Series Routers
  • NCS 1000 Series
  • NCS 5000 Series Routers
  • NCS 5500 Series Routers


Affected software

Cisco IOS XR

How to mitigate CVE-2025-20143

Install updates from vendor's website.

Cisco IOS XR - update to 7.9.1

External References

Related Security Bulletins