Allocation of Resources Without Limits or Throttling in Cisco Systems, Inc products - CVE-2025-20209
Published: March 13, 2025
Cisco IOS XR
NCS 540L
NCS 1004
NCS 1010
NCS 1014
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper handling of malformed packets in the Internet Key Exchange version 2 (IKEv2) function. A remote attacker can send specially crafted IKEv2 packets and cause a denial of service condition on the target system.