Allocation of Resources Without Limits or Throttling in Cisco Systems, Inc products - CVE-2025-20141
Published: March 13, 2025
Vulnerability identifier: #VU105691
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:H/E:U/U:Green
CVE-ID: CVE-2025-20141
CWE-ID: CWE-770
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vendor: Cisco Systems, Inc
Affected software:
Cisco IOS XR
IOS XR White box
NCS540
NCS5500
NCS 5700 Series Routers
Cisco IOS XR
IOS XR White box
NCS540
NCS5500
NCS 5700 Series Routers
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to incorrect handling of packets that are punted to the route processor. A remote attacker on the local network can cause a denial of service condition on the target system.
How to mitigate CVE-2025-20141
Install updates from vendor's website.