Allocation of Resources Without Limits or Throttling in Cisco Systems, Inc products - CVE-2025-20141

 

Allocation of Resources Without Limits or Throttling in Cisco Systems, Inc products - CVE-2025-20141

Published: March 13, 2025


Vulnerability identifier: #VU105691
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:H]
CVE-ID: CVE-2025-20141
CWE-ID: CWE-770
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to incorrect handling of packets that are punted to the route processor. A remote attacker on the local network can cause a denial of service condition on the target system.


Affected software

IOS XR White box
NCS540
NCS5500
NCS 5700 Series Routers
Cisco IOS XR

How to mitigate CVE-2025-20141

Install updates from vendor's website.

Cisco IOS XR - addressed in versions 6.6.2, 6.6.3, 6.6.4, 6.6.25, 6.7.1, 6.7.2, 6.7.3, 6.7.4, 6.7.35, 6.8.1, 6.8.2, 6.9.1, 6.9.2, 7.0.1, 7.0.2, 7.0.90, 7.1.1, 7.1.2, 7.1.3, 7.1.15, 7.1.25, 7.2.0, 7.2.1, 7.2.2, 7.2.12, 7.3.0, 7.3.1, 7.3.2, 7.3.3, 7.3.4, 7.3.5, 7.3.6, 7.3.15, 7.3.16, 7.3.25, 7.3.26, 7.3.27, 7.4.1, 7.4.2, 7.4.15, 7.4.16, 7.5.1, 7.5.2, 7.5.3, 7.5.4, 7.5.5, 7.5.12, 7.6.1, 7.6.2, 7.6.3, 7.6.15, 7.7.1, 7.7.2, 7.7.21, 7.8.1, 7.8.2, 7.8.22, 7.8.23, 7.9.1, 7.9.2, 7.10.1, 7.10.2, 7.11.1, 7.11.2, 7.11.21, 24.1.1, 24.1.2, 24.2.1, 24.2.2, 24.2.11, 24.2.20, 24.3.1, 24.3.2, 24.3.20, 24.4.1, 24.4.10

External References

Related Security Bulletins